{"id":"GHSA-58mr-gqgx-xq4g","summary":"fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority","details":"### Impact\n\n`fast-uri` accepts a host that contains an unbalanced or misplaced authority bracket (`[` or `]`) without reporting an error. A host that starts with `[` but does not end with `]`, such as `[@127.0.0.1`, is neither validated as an IP literal nor canonicalized as a domain name, so `parse()` returns it as the host with `error` undefined, while Node's `URL` (and `http.get`, `axios`, `got`, and other clients built on it) resolve the same string to `127.0.0.1`. An application that reads `parse().host` to make a host decision (an SSRF denylist, a redirect allowlist, or proxy routing) and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried through `normalize()`, `equal()`, and `resolve()`.\n\n### Patches\n\nThis vulnerability has been patched in fast-uri `4.1.4`, `3.1.7`, and `2.4.6`. `parse()` now reports `URI host is malformed.` for any host that contains a bracket but is not a valid `[IPv6]` literal. All users should upgrade.\n\n### Workarounds\n\nIf upgrading is not immediately possible, reject any URL whose host contains a `[` or `]` that is not a well-formed IPv6 literal before making a host decision. Clients that fail closed on credential-bearing URLs, such as Node's global `fetch()`, are not affected by the reported vector.","aliases":["CVE-2026-84394"],"modified":"2026-09-28T21:30:05.360758321Z","published":"2026-09-28T21:23:35Z","database_specific":{"cwe_ids":["CWE-436"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-28T21:23:35Z","nvd_published_at":"2026-09-03T05:16:38Z"},"references":[{"type":"WEB","url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84394"},{"type":"WEB","url":"https://github.com/fastify/fast-uri/pull/214"},{"type":"WEB","url":"https://github.com/fastify/fast-uri/commit/e00815236bc94107e44ef1b2f5318a06bac225c0"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/fastify/fast-uri"},{"type":"WEB","url":"https://github.com/fastify/fast-uri/releases/tag/v2.4.6"},{"type":"WEB","url":"https://github.com/fastify/fast-uri/releases/tag/v3.1.7"},{"type":"WEB","url":"https://github.com/fastify/fast-uri/releases/tag/v4.1.4"}],"affected":[{"package":{"name":"fast-uri","ecosystem":"npm","purl":"pkg:npm/fast-uri"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.4.5"},{"fixed":"2.4.6"}]}],"versions":["2.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-58mr-gqgx-xq4g/GHSA-58mr-gqgx-xq4g.json"}},{"package":{"name":"fast-uri","ecosystem":"npm","purl":"pkg:npm/fast-uri"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.6"},{"fixed":"3.1.7"}]}],"versions":["3.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-58mr-gqgx-xq4g/GHSA-58mr-gqgx-xq4g.json"}},{"package":{"name":"fast-uri","ecosystem":"npm","purl":"pkg:npm/fast-uri"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.1.3"},{"fixed":"4.1.4"}]}],"versions":["4.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-58mr-gqgx-xq4g/GHSA-58mr-gqgx-xq4g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}