VDB
Sign up
HIGH7.5

GHSA-fph4-wmhf-6fwf

fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding

Quick fix

GHSA-fph4-wmhf-6fwf — fast-uri: upgrade to the fixed version with the command below.

npm install fast-uri@2.4.5

Details

### Impact

`fast-uri` decodes a hostname's percent escapes twice in a single `normalize()` or `resolve()` call: once during parsing and again during authority recomposition. A nested percent-encoded host therefore survives the first decode and is turned into a live destination by the second, so `normalize('http://%256c%256f%2563%2561%256c%2568%256f%2573%2574/')` returns `http://localhost/`. Applications that normalize or resolve an untrusted URI before an SSRF check, redirect validation, or host allowlist can be steered to a different destination, including internal addresses such as loopback or a cloud metadata endpoint, than the encoded input appeared to contain. This is an incomplete-fix variant of CVE-2026-6322, whose encoded-authority-delimiter fix introduced the second decode.

### Patches

Fixed in `fast-uri` 2.4.5, 3.1.6, and 4.1.3.

### Workarounds

Reject untrusted URIs whose host component contains an encoded percent sign (`%25`) before passing them to `normalize()` or `resolve()`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-uri
Introduced in: 2.4.1Fixed in: 2.4.5
Fixnpm install fast-uri@2.4.5
npm/fast-uri
Introduced in: 3.1.2Fixed in: 3.1.6
Fixnpm install fast-uri@3.1.6
npm/fast-uri
Introduced in: 4.0.0Fixed in: 4.1.3
Fixnpm install fast-uri@4.1.3

References