CVE-2026-84394High· 7.5▾ Twilightfast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
fast-uri accepts a host that contains an unbalanced or misplaced authority bracket ([ or ]) without reporting an error. A host that starts with [ but does not end with ], such as [@127.0.0.1, is neither validated as an IP literal nor canonicalized as a domain name, so parse() returns it as the host with error undefined, while Node's URL (and http.get, axios, got, and other clients built on it) resolve the same string to 127.0.0.1. An application that reads parse().host to make a host decision (an SSRF denylist, a redirect allowlist, or proxy routing) and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried through normalize(), equal(), and resolve().
This vulnerability has been patched in fast-uri 4.1.4, 3.1.7, and 2.4.6. parse() now reports URI host is malformed. for any host that contains a bracket but is not a valid [IPv6] literal. All users should upgrade.
If upgrading is not immediately possible, reject any URL whose host contains a [ or ] that is not a well-formed IPv6 literal before making a host decision. Clients that fail closed on credential-bearing URLs, such as Node's global fetch(), are not affected by the reported vector.
fast-uri = 2.4.5fast-uri = 3.1.6fast-uri = 4.1.3Upgrade to a patched release:
fast-uri 2.4.6fast-uri 3.1.7fast-uri 4.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84292High· 7.5fast-uri serializes the port component of a URI without validating it
CVE-2026-13676High· 7.5fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs
CVE-2026-86818Medium· 4.8fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3
CVE-2026-6322High· 7.5fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization
CVE-2026-86472Medium· 4.8fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv
CVE-2026-6321High· 7.5fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions