fast-uri vulnerable to host confusion via backslash authority introducer (CVE-2026-18446)
fast-uri versions prior to 2.4.4, 3.1.5, and 4.1.2 improperly parse URIs that use backslash sequences (e.g., \\) as authority introducers instead of the standard double slash (//). This causes a host confusion vulnerability where fast-uri treats the backslash sequence and subsequent text as part of the path, while Node's native WHATWG URL parser treats backslashes as slashes and extracts a different host. This discrepancy can lead to bypassing host-based security policies such as allowlists, denylists, SSRF filtering, redirect validation, or proxy routing. The vulnerability is tracked as CVE-2026-18446 and has a high severity with a CVSS score of 7.5.
AI Analysis
Technical Summary
The fast-uri library versions before 2.4.4, between 3.0.0 and 3.1.5, and between 4.0.0 and 4.1.2 have a vulnerability where they require a literal '//' to recognize a URI authority. If a URI uses backslash sequences (\\, /\, \/) instead of '//', fast-uri fails to parse the authority and treats the sequence and everything after it as part of the path. In contrast, Node's WHATWG URL parser treats '\\' as equivalent to '/' for certain schemes (http, https, ws, wss, ftp, file), extracting a different host. This mismatch can cause applications that rely on fast-uri for host-based policy enforcement to be bypassed when the same URL is later processed by Node's URL or fetch consumers, potentially redirecting to unintended hosts. The issue is fixed in fast-uri versions 2.4.4, 3.1.5, and 4.1.2.
Potential Impact
This vulnerability allows attackers to bypass host-based security controls that rely on fast-uri for URI parsing. Because fast-uri and Node's WHATWG URL parser interpret backslash sequences differently, an attacker can craft URLs that appear safe to fast-uri but resolve to malicious hosts when processed by Node's native URL parser. This can lead to security policy bypasses such as SSRF, unauthorized redirects, or proxy routing to unintended destinations. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
Upgrade fast-uri to version 2.4.4, 3.1.5, or 4.1.2 or later. No workarounds are available. Applying the official patch is the only effective mitigation.
fast-uri vulnerable to host confusion via backslash authority introducer (CVE-2026-18446)
Description
fast-uri versions prior to 2.4.4, 3.1.5, and 4.1.2 improperly parse URIs that use backslash sequences (e.g., \\) as authority introducers instead of the standard double slash (//). This causes a host confusion vulnerability where fast-uri treats the backslash sequence and subsequent text as part of the path, while Node's native WHATWG URL parser treats backslashes as slashes and extracts a different host. This discrepancy can lead to bypassing host-based security policies such as allowlists, denylists, SSRF filtering, redirect validation, or proxy routing. The vulnerability is tracked as CVE-2026-18446 and has a high severity with a CVSS score of 7.5.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fast-uri library versions before 2.4.4, between 3.0.0 and 3.1.5, and between 4.0.0 and 4.1.2 have a vulnerability where they require a literal '//' to recognize a URI authority. If a URI uses backslash sequences (\\, /\, \/) instead of '//', fast-uri fails to parse the authority and treats the sequence and everything after it as part of the path. In contrast, Node's WHATWG URL parser treats '\\' as equivalent to '/' for certain schemes (http, https, ws, wss, ftp, file), extracting a different host. This mismatch can cause applications that rely on fast-uri for host-based policy enforcement to be bypassed when the same URL is later processed by Node's URL or fetch consumers, potentially redirecting to unintended hosts. The issue is fixed in fast-uri versions 2.4.4, 3.1.5, and 4.1.2.
Potential Impact
This vulnerability allows attackers to bypass host-based security controls that rely on fast-uri for URI parsing. Because fast-uri and Node's WHATWG URL parser interpret backslash sequences differently, an attacker can craft URLs that appear safe to fast-uri but resolve to malicious hosts when processed by Node's native URL parser. This can lead to security policy bypasses such as SSRF, unauthorized redirects, or proxy routing to unintended destinations. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
Upgrade fast-uri to version 2.4.4, 3.1.5, or 4.1.2 or later. No workarounds are available. Applying the official patch is the only effective mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7p8r-x3mc-p8w7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-18446"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a710654bf32cb7a34393217
Added to database: 08/03/2026, 21:21:24 UTC
Last enriched: 08/03/2026, 21:25:34 UTC
Last updated: 08/04/2026, 00:23:02 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.