PT-2026-91922 · Npm · Fast-Uri
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
fast-uri versions prior to 2.4.7
fast-uri versions 3.0.0 through 3.1.7
fast-uri versions 4.0.0 through 4.1.4
Description
The software folds the host to lowercase before percent-decoding it. Consequently, a percent-encoded uppercase octet, such as
%41, decodes to a literal uppercase character that is not folded. In scheme-relative references (e.g., //host), the absence of a scheme prevents the host canonicalization that would typically correct this, causing the parse, normalize, and equal functions to disagree on the same host. Applications performing case-sensitive host decisions, such as those using an allowlist or denylist, can be bypassed using percent-encoded uppercase octets. Since DNS and HTTP hostnames are case-insensitive, the bypassed input still reaches the intended destination.Recommendations
Update to version 2.4.7 or later.
Update to version 3.1.8 or later.
Update to version 4.1.5 or later.
As a temporary workaround, compare hosts case-insensitively by lowercasing the parsed host before making any allowlist or denylist decisions.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fast-Uri