VDB
Sign up
HIGH7.5

GHSA-f65p-4m7j-42xc

fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization

Quick fix

GHSA-f65p-4m7j-42xc — fast-uri: upgrade to the fixed version with the command below.

npm install fast-uri@2.4.5

Details

### Impact

`fast-uri` does not validate the complete RFC 3986 grammar for bracketed IPv6 literals, so a malformed literal with invalid trailing text is silently truncated to a different valid IPv6 address with no error reported. For example, `normalize('http://[::not-valid]/private')` returns `http://[::]/private`, and `[fc00::not-hex]` and `[fe80::not-hex]` collapse to `[fc00::]` and `[fe80::]`. An application that normalizes an untrusted URL before an outbound request, redirect, or host-policy check can be routed to a local or private address such as loopback (`::1`), unique-local, or link-local. Because `parse().error` is unset for these inputs, checking it does not protect the consumer.

### Patches

Upgrade to `fast-uri` 2.4.5, 3.1.6, or 4.1.3. Malformed IPv6 literals are now rejected with a host error instead of being normalized to a valid address.

### Workarounds

Reject untrusted URLs whose host is a bracketed IPv6 literal before passing them to `fast-uri`, or route outbound requests against an explicit allowlist of addresses rather than trusting the normalized host.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-uri
Introduced in: 2.3.1Fixed in: 2.4.5
Fixnpm install fast-uri@2.4.5
npm/fast-uri
Introduced in: 3.0.0Fixed in: 3.1.6
Fixnpm install fast-uri@3.1.6
npm/fast-uri
Introduced in: 4.0.0Fixed in: 4.1.3
Fixnpm install fast-uri@4.1.3

References