PT-2026-91922 · Npm · Fast-Uri

·

CVE-2026-86472

·

Published

2026-09-15

·

Updated

2026-09-29

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions fast-uri versions prior to 2.4.7 fast-uri versions 3.0.0 through 3.1.7 fast-uri versions 4.0.0 through 4.1.4
Description The software folds the host to lowercase before percent-decoding it. Consequently, a percent-encoded uppercase octet, such as %41, decodes to a literal uppercase character that is not folded. In scheme-relative references (e.g., //host), the absence of a scheme prevents the host canonicalization that would typically correct this, causing the parse, normalize, and equal functions to disagree on the same host. Applications performing case-sensitive host decisions, such as those using an allowlist or denylist, can be bypassed using percent-encoded uppercase octets. Since DNS and HTTP hostnames are case-insensitive, the bypassed input still reaches the intended destination.
Recommendations Update to version 2.4.7 or later. Update to version 3.1.8 or later. Update to version 4.1.5 or later. As a temporary workaround, compare hosts case-insensitively by lowercasing the parsed host before making any allowlist or denylist decisions.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86472
GHSA-HRR3-GC8F-F4QJ

Affected Products

Fast-Uri