VDB
KO
HIGH 7.5

GHSA-7p8r-x3mc-p8w7

fast-uri vulnerable to host confusion via backslash authority introducer

Quick fix

GHSA-7p8r-x3mc-p8w7 — fast-uri: upgrade to the fixed version with the command below.

npm install fast-uri@2.4.4

Details

### Impact

`fast-uri` v4.1.1 and earlier require a literal `//` to recognize a URI authority, so a reference that uses `\\`, `/\`, or `\/` as the authority introducer (in place of `//`, after an optional scheme) is parsed with no authority: the sequence and everything after it fold into the path. Node's native WHATWG `URL` (used by `fetch()`, `undici`, and Node's `http`/`https` clients) instead treats `\` as interchangeable with `/` for special schemes (`http`, `https`, `ws`, `wss`, `ftp`, `file`), so the two parsers extract different hosts from the same input.

For example, `fast-uri` resolves `\\evil.com/path` against base `https://allowed.com/` to `https://allowed.com/%5C%5Cevil.com/path` (confined to the trusted host), while Node's WHATWG URL resolves the same reference to `https://evil.com/path`.

Applications that use `fast-uri` to enforce host-based policy (allowlists, denylists, loopback/SSRF filtering, redirect validation, outbound proxy routing) before passing the same URL into Node's URL or `fetch()` consumers see a policy/use desync and can be steered to an unintended destination.

### Patches

Upgrade to `fast-uri` v4.1.2, v3.1.5, v2.4.4.

### Workarounds

None. Upgrade to the patched version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / fast-uri
Introduced in: 0 Fixed in: 2.4.4
Fix npm install fast-uri@2.4.4
npm / fast-uri
Introduced in: 3.0.0 Fixed in: 3.1.5
Fix npm install fast-uri@3.1.5
npm / fast-uri
Introduced in: 4.0.0 Fixed in: 4.1.2
Fix npm install fast-uri@4.1.2

References