GHSA-jqff-g426-hqxpHighCVSS 7.5

fast-uri vulnerable to host confusion via percent-encoded scheme normalization

Published
September 2, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

fast-uri decodes percent-encoded characters in the scheme component with the legacy global unescape() and serializes the result back as raw characters, without re-escaping it or validating it as a scheme. A scheme that decodes to characters outside the RFC 3986 scheme grammar can therefore introduce structure the original input did not contain.

For example, %2f%2fevil.example:/pwn parses with no authority (parse().host is undefined), but resolve() and normalize() return //evil.example:/pwn, which reparses with host evil.example. The %uXXXX form (%u002f%u002fevil.example:/pwn) produces the same result, and a scheme containing %0d%0a reaches the output as a raw CR LF.

Applications that normalize or resolve untrusted URLs before a redirect check, host allowlist, or outbound request decision, especially ones that treat a missing authority as same-origin, can be steered to an attacker-chosen authority, and a normalized URI placed in a response header can carry an injected CR LF.

Patches

Upgrade to fast-uri >= 4.1.3, or >= 3.1.6 in the v3.x release line, or >= 2.4.5 in the v2.x release line.

Workarounds

None. Upgrade to the patched version.

🎯 Affected products3

  • npm/fast-uri:>= 2.3.1, < 2.4.5
  • npm/fast-uri:>= 3.0.0, < 3.1.6
  • npm/fast-uri:>= 4.0.0, < 4.1.3

🔗 References (10)