fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority (CVE-2026-84394)
The fast-uri library has a vulnerability where it accepts hosts with unbalanced or misplaced brackets in the URI authority without error. This can cause discrepancies between how fast-uri parses the host and how Node.js URL clients resolve it, potentially leading to host confusion. This affects applications that rely on fast-uri's parse().host for security decisions such as SSRF denylisting or redirect allowlisting. The issue is patched in fast-uri versions 4.1.4, 3.1.7, and 2.4.6.
AI Analysis
Technical Summary
fast-uri versions prior to 4.1.4, 3.1.7, and 2.4.6 accept URI hosts containing unbalanced or misplaced brackets (e.g., a host starting with '[' but missing a closing ']'). Such hosts are neither validated as IP literals nor canonicalized as domain names, causing parse() to return the malformed host without error. Meanwhile, Node.js URL clients resolve the same host string differently, potentially to a valid IP address like 127.0.0.1. This mismatch can lead to security bypasses in applications that use fast-uri's parse().host for host-based security policies but pass the original URL to HTTP clients. The vulnerability is identified as CVE-2026-84394 and has a CVSS 3.1 score of 7.5 (high severity).
Potential Impact
Applications using fast-uri versions before the patched releases may incorrectly trust the host value returned by parse().host when making security decisions such as SSRF denylisting, redirect allowlisting, or proxy routing. Because the host string is not validated or canonicalized properly, an attacker can craft URLs with unclosed brackets that bypass these checks, while the actual HTTP client resolves the host differently, potentially reaching unintended destinations. This can lead to security policy bypass and potential information disclosure or unauthorized access.
Mitigation Recommendations
A patch is available and should be applied by upgrading fast-uri to versions 4.1.4, 3.1.7, or 2.4.6. The patch causes parse() to report an error for malformed hosts containing brackets that are not valid IPv6 literals. If immediate upgrade is not possible, applications should reject any URL whose host contains '[' or ']' that is not a well-formed IPv6 literal before making host-based security decisions. Note that clients that fail closed on credential-bearing URLs, such as Node's global fetch(), are not affected by this vulnerability.
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority (CVE-2026-84394)
Description
The fast-uri library has a vulnerability where it accepts hosts with unbalanced or misplaced brackets in the URI authority without error. This can cause discrepancies between how fast-uri parses the host and how Node.js URL clients resolve it, potentially leading to host confusion. This affects applications that rely on fast-uri's parse().host for security decisions such as SSRF denylisting or redirect allowlisting. The issue is patched in fast-uri versions 4.1.4, 3.1.7, and 2.4.6.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
fast-uri versions prior to 4.1.4, 3.1.7, and 2.4.6 accept URI hosts containing unbalanced or misplaced brackets (e.g., a host starting with '[' but missing a closing ']'). Such hosts are neither validated as IP literals nor canonicalized as domain names, causing parse() to return the malformed host without error. Meanwhile, Node.js URL clients resolve the same host string differently, potentially to a valid IP address like 127.0.0.1. This mismatch can lead to security bypasses in applications that use fast-uri's parse().host for host-based security policies but pass the original URL to HTTP clients. The vulnerability is identified as CVE-2026-84394 and has a CVSS 3.1 score of 7.5 (high severity).
Potential Impact
Applications using fast-uri versions before the patched releases may incorrectly trust the host value returned by parse().host when making security decisions such as SSRF denylisting, redirect allowlisting, or proxy routing. Because the host string is not validated or canonicalized properly, an attacker can craft URLs with unclosed brackets that bypass these checks, while the actual HTTP client resolves the host differently, potentially reaching unintended destinations. This can lead to security policy bypass and potential information disclosure or unauthorized access.
Mitigation Recommendations
A patch is available and should be applied by upgrading fast-uri to versions 4.1.4, 3.1.7, or 2.4.6. The patch causes parse() to report an error for malformed hosts containing brackets that are not valid IPv6 literals. If immediate upgrade is not possible, applications should reject any URL whose host contains '[' or ']' that is not a well-formed IPv6 literal before making host-based security decisions. Note that clients that fail closed on credential-bearing URLs, such as Node's global fetch(), are not affected by this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-58mr-gqgx-xq4g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-84394"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abb418ff7a7c54106cc3712
Added to database: 09/29/2026, 04:41:51 UTC
Last enriched: 09/29/2026, 04:49:42 UTC
Last updated: 09/29/2026, 18:11:21 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.