CVE-2026-84394
- EPSS 0.22%
- Veröffentlicht 02.09.2026 20:25:35
- Zuletzt bearbeitet 04.09.2026 16:12:20
fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized ...
CVE-2026-84292
- EPSS 0.23%
- Veröffentlicht 02.09.2026 20:17:39
- Zuletzt bearbeitet 06.10.2026 22:10:00
fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject aut...
CVE-2026-76172
- EPSS 0.25%
- Veröffentlicht 24.08.2026 11:16:40
- Zuletzt bearbeitet 02.09.2026 14:43:42
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a ...
CVE-2026-75931
- EPSS 0.25%
- Veröffentlicht 24.08.2026 10:16:40
- Zuletzt bearbeitet 02.09.2026 14:44:52
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set....
CVE-2026-75975
- EPSS 0.23%
- Veröffentlicht 24.08.2026 10:16:40
- Zuletzt bearbeitet 02.09.2026 14:44:17
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned int...
CVE-2026-75899
- EPSS 0.23%
- Veröffentlicht 24.08.2026 10:16:39
- Zuletzt bearbeitet 02.09.2026 14:43:19
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded ...
CVE-2026-18446
- EPSS 0.22%
- Veröffentlicht 31.07.2026 14:37:01
- Zuletzt bearbeitet 02.09.2026 14:42:38
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward sla...
CVE-2026-16221
- EPSS 0.25%
- Veröffentlicht 19.07.2026 14:08:32
- Zuletzt bearbeitet 05.08.2026 19:46:09
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici...
CVE-2026-13676
- EPSS 0.38%
- Veröffentlicht 29.06.2026 13:22:44
- Zuletzt bearbeitet 11.09.2026 13:17:06
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Uni...
CVE-2026-6322
- EPSS 0.48%
- Veröffentlicht 05.05.2026 11:16:33
- Zuletzt bearbeitet 10.09.2026 13:20:29
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emi...