Back

HIGH

fast-uri vulnerable to host confusion via percent-encoded authority delimiters

Published May 5, 2026

Description

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.

Affected products

Remediation

Red Hat statement

This Important flaw in the `fast-uri` library allows an attacker to bypass security controls in Red Hat products that process Uniform Resource Identifiers (URIs). By crafting a malicious URI with percent-encoded authority delimiters, an attacker can cause the library to incorrectly interpret the URI's authority, potentially redirecting applications to an unintended domain. This could lead to a bypass of host allowlist checks, redirect validation, or outbound request routing.

Weaknesses (2)

References (52)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openjs
Published May 5, 2026
Updated Sep 10, 2026
Reserved Apr 14, 2026
CISA Vulnrichment
Updated May 5, 2026
NVD
Status Modified
Modified Sep 10, 2026
Red Hat
Severity Important
Public date May 5, 2026
ENISA EUVD
Assigner openjs
Published May 5, 2026
Updated Sep 10, 2026
Exploited since n/a
EUVD-2026-27248 GHSA-V39H-62P7-JPJC