GHSA-4c8g-83qw-93j6

    Dashboard / Vulnerabilities / GHSA-4c8g-83qw-93j6

    GHSA-4c8g-83qw-93j6

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: fast-uri vulnerable to host confusion via failed IDN canonicalization

    Details: ### Impact `fast-uri` versions `>= 2.3.1, <= 4.0.0` fail to canonicalize Unicode/IDN hostnames for HTTP-family URLs. The IDN conversion path calls `URL.domainToASCII(...)` on the global WHATWG `URL` constructor, where that helper does not exist. The resulting `TypeError` is silently routed into `parsed.error`, but `parse()`, `normalize()`, and `equal()` all return with the host left in its original Unicode form. For example, `http://127。0。0。1/` is treated by `fast-uri` as host `127。0。0。1`, while Node's WHATWG URL parser and `fetch()` canonicalize the same input to `127.0.0.1`. Applications that use `fast-uri` to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL into Node's URL or `fetch()` consumers see a policy/use desync and can be steered to an unintended destination. ### Patches Upgrade to `fast-uri` v4.0.1, v3.1.3, or v2.4.2 ### Workarounds None. Upgrade to the patched version.

    References: https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6, https://nvd.nist.gov/vuln/detail/CVE-2026-13676, https://github.com/fastify/fast-uri/pull/188, https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05, https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bd, https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1d, https://access.redhat.com/errata/RHSA-2026:54760, https://access.redhat.com/errata/RHSA-2026:56366, https://access.redhat.com/errata/RHSA-2026:56431, https://access.redhat.com/errata/RHSA-2026:57013, https://access.redhat.com/errata/RHSA-2026:57191, https://access.redhat.com/errata/RHSA-2026:57194, https://access.redhat.com/errata/RHSA-2026:57590, https://access.redhat.com/errata/RHSA-2026:59593, https://access.redhat.com/errata/RHSA-2026:60386, https://access.redhat.com/errata/RHSA-2026:60520, https://access.redhat.com/errata/RHSA-2026:61314, https://access.redhat.com/errata/RHSA-2026:63371, https://access.redhat.com/security/cve/CVE-2026-13676, https://bugzilla.redhat.com/show_bug.cgi?id=2494197, https://cna.openjsf.org/security-advisories.html, https://github.com/fastify/fast-uri, https://github.com/fastify/fast-uri/releases/tag/v2.4.2, https://github.com/fastify/fast-uri/releases/tag/v3.1.3, https://github.com/fastify/fast-uri/releases/tag/v4.0.1, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json, https://access.redhat.com/errata/RHSA-2026:37186, https://access.redhat.com/errata/RHSA-2026:37585, https://access.redhat.com/errata/RHSA-2026:37628, https://access.redhat.com/errata/RHSA-2026:40118, https://access.redhat.com/errata/RHSA-2026:40262, https://access.redhat.com/errata/RHSA-2026:40765, https://access.redhat.com/errata/RHSA-2026:40945, https://access.redhat.com/errata/RHSA-2026:41066, https://access.redhat.com/errata/RHSA-2026:41928, https://access.redhat.com/errata/RHSA-2026:41929, https://access.redhat.com/errata/RHSA-2026:42815, https://access.redhat.com/errata/RHSA-2026:43038, https://access.redhat.com/errata/RHSA-2026:44239, https://access.redhat.com/errata/RHSA-2026:44268, https://access.redhat.com/errata/RHSA-2026:47728, https://access.redhat.com/errata/RHSA-2026:48124, https://access.redhat.com/errata/RHSA-2026:48126, https://access.redhat.com/errata/RHSA-2026:49642, https://access.redhat.com/errata/RHSA-2026:50340, https://access.redhat.com/errata/RHSA-2026:50479, https://access.redhat.com/errata/RHSA-2026:50758, https://access.redhat.com/errata/RHSA-2026:51196, https://access.redhat.com/errata/RHSA-2026:51197, https://access.redhat.com/errata/RHSA-2026:51342, https://access.redhat.com/errata/RHSA-2026:51348, https://access.redhat.com/errata/RHSA-2026:51349

    Affected packages

    Package

    Name: fast-uri

    Purl: pkg:npm/fast-uri

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.0.0
    Fixed -4.0.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High