GHSA-v2hh-gcrm-f6hx

Suggest an improvement
Source
https://github.com/advisories/GHSA-v2hh-gcrm-f6hx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v2hh-gcrm-f6hx/GHSA-v2hh-gcrm-f6hx.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-v2hh-gcrm-f6hx
Aliases
Downstream
CGA (274)
MINI (38)
Published
2026-07-21T22:08:28Z
Modified
2026-08-24T00:36:58Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
fast-uri vulnerable to host confusion via literal backslash authority delimiter
Details

Impact

fast-uri v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node's native WHATWG URL (used by fetch(), undici, and Node's http/https clients) normalizes \ to / for special schemes (http, https, ws, wss, ftp, file), so the two parsers extract different hosts from the same input string.

For example, http://evil.com\@allowed.com is treated by fast-uri as host allowed.com with userinfo evil.com\, while Node's WHATWG URL parser and fetch() see host evil.com with path /@allowed.com.

Applications that use fast-uri to enforce host-based policy (allowlists, denylists, loopback/SSRF filtering, redirect validation, outbound proxy routing) before passing the same URL into Node's URL or fetch() consumers see a policy/use desync and can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts.

Patches

Upgrade to fast-uri v4.1.1, v3.1.4, or v2.4.3.

Workarounds

None. Upgrade to the patched version.

Database specific
{
    "cwe_ids": [
        "CWE-436"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-21T22:08:28Z",
    "nvd_published_at": "2026-07-19T15:16:49Z",
    "severity": "HIGH"
}
References

Affected packages

npm / fast-uri

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.3.1
Fixed
2.4.3

Database specific

last_known_affected_version_range
"<= 2.4.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v2hh-gcrm-f6hx/GHSA-v2hh-gcrm-f6hx.json"

npm / fast-uri

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.1.4

Database specific

last_known_affected_version_range
"<= 3.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v2hh-gcrm-f6hx/GHSA-v2hh-gcrm-f6hx.json"

npm / fast-uri

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.1.1

Database specific

last_known_affected_version_range
"<= 4.1.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v2hh-gcrm-f6hx/GHSA-v2hh-gcrm-f6hx.json"