Skip to main content
EPSS 0.4%top 71%

fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority (CVE-2026-84394)

0
High
Published: 09/28/2026 (09/28/2026, 21:23:35 UTC)
Source: GCVE Database
Product: fast-uri

Description

The fast-uri library has a vulnerability where it accepts hosts with unbalanced or misplaced brackets in the URI authority without error. This can cause discrepancies between how fast-uri parses the host and how Node.js URL clients resolve it, potentially leading to host confusion. This affects applications that rely on fast-uri's parse().host for security decisions such as SSRF denylisting or redirect allowlisting. The issue is patched in fast-uri versions 4.1.4, 3.1.7, and 2.4.6.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected software

npmghsa
fast-uri
Affected versions
>=4.1.3 <4.1.4=4.1.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 04:49:42 UTC

Technical Analysis

fast-uri versions prior to 4.1.4, 3.1.7, and 2.4.6 accept URI hosts containing unbalanced or misplaced brackets (e.g., a host starting with '[' but missing a closing ']'). Such hosts are neither validated as IP literals nor canonicalized as domain names, causing parse() to return the malformed host without error. Meanwhile, Node.js URL clients resolve the same host string differently, potentially to a valid IP address like 127.0.0.1. This mismatch can lead to security bypasses in applications that use fast-uri's parse().host for host-based security policies but pass the original URL to HTTP clients. The vulnerability is identified as CVE-2026-84394 and has a CVSS 3.1 score of 7.5 (high severity).

Potential Impact

Applications using fast-uri versions before the patched releases may incorrectly trust the host value returned by parse().host when making security decisions such as SSRF denylisting, redirect allowlisting, or proxy routing. Because the host string is not validated or canonicalized properly, an attacker can craft URLs with unclosed brackets that bypass these checks, while the actual HTTP client resolves the host differently, potentially reaching unintended destinations. This can lead to security policy bypass and potential information disclosure or unauthorized access.

Mitigation Recommendations

A patch is available and should be applied by upgrading fast-uri to versions 4.1.4, 3.1.7, or 2.4.6. The patch causes parse() to report an error for malformed hosts containing brackets that are not valid IPv6 literals. If immediate upgrade is not possible, applications should reject any URL whose host contains '[' or ']' that is not a well-formed IPv6 literal before making host-based security decisions. Note that clients that fail closed on credential-bearing URLs, such as Node's global fetch(), are not affected by this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-58mr-gqgx-xq4g
Osv Schema Version
1.4.0
Aliases
["CVE-2026-84394"]
Ecosystems
["npm"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6abb418ff7a7c54106cc3712

Added to database: 09/29/2026, 04:41:51 UTC

Last enriched: 09/29/2026, 04:49:42 UTC

Last updated: 09/29/2026, 18:11:21 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses