PT-2026-66759 · Npm · Fast-Uri

·

CVE-2026-18446

·

Published

2026-07-31

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions fast-uri versions prior to 4.1.2 fast-uri versions prior to 3.1.5 fast-uri versions prior to 2.4.4
Description The software requires a literal double forward slash to recognize a URI authority. If a backslash-based introducer is used instead (such as backslash backslash, forward slash backslash, or backslash forward slash), the input is parsed without an authority and folded into the path. This creates a discrepancy with Node's native WHATWG URL parser, which treats backslashes as interchangeable with forward slashes for special schemes. Applications using the software to enforce host-based policies, such as allowlists, SSRF filtering, or redirect validation, before passing the URL to Node's URL or fetch consumers, may be steered to an unintended host.
Recommendations Update to version 4.1.2. Update to version 3.1.5. Update to version 2.4.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18446
GHSA-7P8R-X3MC-P8W7
RHSA-2026:49387
RHSA-2026:49401

Affected Products

Fast-Uri