GHSA-f65p-4m7j-42xcHighCVSS 7.5

fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization

Published
September 2, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

fast-uri does not validate the complete RFC 3986 grammar for bracketed IPv6 literals, so a malformed literal with invalid trailing text is silently truncated to a different valid IPv6 address with no error reported. For example, normalize('http://[::not-valid]/private') returns http://[::]/private, and [fc00::not-hex] and [fe80::not-hex] collapse to [fc00::] and [fe80::]. An application that normalizes an untrusted URL before an outbound request, redirect, or host-policy check can be routed to a local or private address such as loopback (::1), unique-local, or link-local. Because parse().error is unset for these inputs, checking it does not protect the consumer.

Patches

Upgrade to fast-uri 2.4.5, 3.1.6, or 4.1.3. Malformed IPv6 literals are now rejected with a host error instead of being normalized to a valid address.

Workarounds

Reject untrusted URLs whose host is a bracketed IPv6 literal before passing them to fast-uri, or route outbound requests against an explicit allowlist of addresses rather than trusting the normalized host.

🎯 Affected products3

  • npm/fast-uri:>= 2.3.1, < 2.4.5
  • npm/fast-uri:>= 3.0.0, < 3.1.6
  • npm/fast-uri:>= 4.0.0, < 4.1.3

🔗 References (10)