VulnSea

fast-uri vulnerabilities

CVEs whose affected-version data names the fast-uri package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-86818Medium· 4.8
1w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved nam…

Sunlitfast-uri · fast-uriEPSS 0.16%via NVD
CVE-2026-86472Medium· 4.8
1w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the …

Sunlitfast-uri · fast-uriEPSS 0.16%via NVD
CVE-2026-13676High· 7.5
2mo ago

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its…

Twilightopenjsf · fast-uriEPSS 0.48%via NVD
CVE-2026-6322High· 7.5
4mo ago

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different doma…

Twilightopenjsf · fast-uriEPSS 0.51%via NVD
CVE-2026-6321High· 7.5
4mo ago

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct …

Twilightopenjsf · fast-uriEPSS 0.63%via NVD
fast-uri vulnerabilities (CVEs) · VulnSea