GHSA-v2hh-gcrm-f6hx

    Dashboard / Vulnerabilities / GHSA-v2hh-gcrm-f6hx

    GHSA-v2hh-gcrm-f6hx

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: fast-uri vulnerable to host confusion via literal backslash authority delimiter

    Details: ### Impact `fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node's native WHATWG `URL` (used by `fetch()`, `undici`, and Node's `http`/`https` clients) normalizes `\` to `/` for special schemes (`http`, `https`, `ws`, `wss`, `ftp`, `file`), so the two parsers extract different hosts from the same input string. For example, `http://evil.com\@allowed.com` is treated by `fast-uri` as host `allowed.com` with userinfo `evil.com\`, while Node's WHATWG URL parser and `fetch()` see host `evil.com` with path `/@allowed.com`. Applications that use `fast-uri` to enforce host-based policy (allowlists, denylists, loopback/SSRF filtering, redirect validation, outbound proxy routing) before passing the same URL into Node's URL or `fetch()` consumers see a policy/use desync and can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts. ### Patches Upgrade to `fast-uri` v4.1.1, v3.1.4, or v2.4.3. ### Workarounds None. Upgrade to the patched version.

    Affected packages

    Package

    Name: fast-uri

    Purl: pkg:npm/fast-uri

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.3.1
    Fixed -2.4.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-v2hh-gcrm-f6hx | CVE-DB