← Volver al buscador de CVEs

CVE-2026-18446

fast-uri

Descripción

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node-s native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applications that use fast-uri to enforce host based policy such as allowlists, SSRF filtering, or redirect validation before passing the same URL into Node-s URL or fetch consumers can be steered to an unintended host. Upgrade to fast-uri 4.1.2, 3.1.5, or 2.4.4.

CVSS 7.5EPSS 0.22100000000000003%Riesgo 0.76
Ver fuente
Publicación
2026-07-31 15:16:27
Versiones afectadas
<4.1.2, <3.1.5, <2.4.4
Tipo
Librería
Última modificación
2026-07-31 18:17:13
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N