GHSA-jqff-g426-hqxp

    Dashboard / Vulnerabilities / GHSA-jqff-g426-hqxp

    GHSA-jqff-g426-hqxp

    Published: 2 Sept 2026Last Modified: 3 Sept 2026

    Summary: fast-uri vulnerable to host confusion via percent-encoded scheme normalization

    Details: ### Impact `fast-uri` decodes percent-encoded characters in the scheme component with the legacy global `unescape()` and serializes the result back as raw characters, without re-escaping it or validating it as a scheme. A scheme that decodes to characters outside the RFC 3986 scheme grammar can therefore introduce structure the original input did not contain. For example, `%2f%2fevil.example:/pwn` parses with no authority (`parse().host` is `undefined`), but `resolve()` and `normalize()` return `//evil.example:/pwn`, which reparses with host `evil.example`. The `%uXXXX` form (`%u002f%u002fevil.example:/pwn`) produces the same result, and a scheme containing `%0d%0a` reaches the output as a raw CR LF. Applications that normalize or resolve untrusted URLs before a redirect check, host allowlist, or outbound request decision, especially ones that treat a missing authority as same-origin, can be steered to an attacker-chosen authority, and a normalized URI placed in a response header can carry an injected CR LF. ### Patches Upgrade to `fast-uri` >= 4.1.3, or >= 3.1.6 in the v3.x release line, or >= 2.4.5 in the v2.x release line. ### Workarounds None. Upgrade to the patched version.

    Affected packages

    Package

    Name: fast-uri

    Purl: pkg:npm/fast-uri

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.3.1
    Fixed -2.4.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High