VDB
Sign up
HIGH7.5

GHSA-5jgf-p345-68v8

fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references

Quick fix

GHSA-5jgf-p345-68v8 — fast-uri: upgrade to the fixed version with the command below.

npm install fast-uri@2.4.5

Details

### Impact

`fast-uri` canonicalizes a host to its ASCII form only when the input carries an explicit scheme. When `resolve()` resolves a scheme-relative reference (`//host/`) against a scheme-bearing base, it still emits the host verbatim even though the effective scheme is known, so re-parsing the resolved URI yields a different host than the one `resolve()` returned. An application that resolves an untrusted reference with `fast-uri` and then checks or routes on the resulting host can make a policy decision on one host and reach another. This is an incomplete-fix variant of CVE-2026-13676, whose IDN canonicalization was applied only to the scheme-bearing form.

### Patches

Upgrade to `fast-uri` 2.4.5, 3.1.6, or 4.1.3. `resolve()` now canonicalizes the host once the effective scheme is known, and fails closed if a raw non-ASCII host cannot be converted.

### Workarounds

Resolve scheme-relative references against a base that carries a scheme before performing any host-policy or origin check.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-uri
Introduced in: 2.4.2Fixed in: 2.4.5
Fixnpm install fast-uri@2.4.5
npm/fast-uri
Introduced in: 3.1.3Fixed in: 3.1.6
Fixnpm install fast-uri@3.1.6
npm/fast-uri
Introduced in: 4.0.1Fixed in: 4.1.3
Fixnpm install fast-uri@4.1.3

References