---
id: CVE-2026-84394
aliases:
  - GHSA-58mr-gqgx-xq4g
title: >-
  fast-uri vulnerable to host confusion via an unclosed bracket in the URI
  authority
summary: >-
  fast-uri vulnerable to host confusion via an unclosed bracket in the URI
  authority
severity: high
cvss: 7.5
cwe:
  - CWE-436
vendor: fast-uri
product: fast-uri
ecosystem: npm
affected:
  - fast-uri = 2.4.5
  - fast-uri = 3.1.6
  - fast-uri = 4.1.3
patched:
  - fast-uri 2.4.6
  - fast-uri 3.1.7
  - fast-uri 4.1.4
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T21:23:36Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-58mr-gqgx-xq4g'
references:
  - url: >-
      https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84394'
  - url: 'https://github.com/fastify/fast-uri/pull/214'
  - url: >-
      https://github.com/fastify/fast-uri/commit/e00815236bc94107e44ef1b2f5318a06bac225c0
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v2.4.6'
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v3.1.7'
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v4.1.4'
  - url: 'https://github.com/advisories/GHSA-58mr-gqgx-xq4g'
tags:
  - ghsa
  - npm
ingestedAt: '2026-09-28T22:22:13.613Z'
---

## Overview

### Impact

`fast-uri` accepts a host that contains an unbalanced or misplaced authority bracket (`[` or `]`) without reporting an error. A host that starts with `[` but does not end with `]`, such as `[@127.0.0.1`, is neither validated as an IP literal nor canonicalized as a domain name, so `parse()` returns it as the host with `error` undefined, while Node's `URL` (and `http.get`, `axios`, `got`, and other clients built on it) resolve the same string to `127.0.0.1`. An application that reads `parse().host` to make a host decision (an SSRF denylist, a redirect allowlist, or proxy routing) and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried through `normalize()`, `equal()`, and `resolve()`.

### Patches

This vulnerability has been patched in fast-uri `4.1.4`, `3.1.7`, and `2.4.6`. `parse()` now reports `URI host is malformed.` for any host that contains a bracket but is not a valid `[IPv6]` literal. All users should upgrade.

### Workarounds

If upgrading is not immediately possible, reject any URL whose host contains a `[` or `]` that is not a well-formed IPv6 literal before making a host decision. Clients that fail closed on credential-bearing URLs, such as Node's global `fetch()`, are not affected by the reported vector.

## Affected packages

- `fast-uri = 2.4.5`
- `fast-uri = 3.1.6`
- `fast-uri = 4.1.3`

## Remediation

Upgrade to a patched release:

- `fast-uri 2.4.6`
- `fast-uri 3.1.7`
- `fast-uri 4.1.4`
