CVE-2026-84292: Authority Injection in fast-uri via Unvalidated Port Component
Vulnerability ID: CVE-2026-84292
CVSS Score: 7.5
Published: 2026-09-28
An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.
TL;DR
Unvalidated port serialization in fast-uri allows remote attackers to perform authority injection and redirect connections to external hosts.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-116
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- EPSS Score: 0.0038
- Impact: Integrity
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- fast-uri
-
fast-uri: < 2.4.6 (Fixed in:
2.4.6) -
fast-uri: >= 3.0.0 < 3.1.7 (Fixed in:
3.1.7) -
fast-uri: >= 4.0.0 < 4.1.4 (Fixed in:
4.1.4)
Code Analysis
Commit: 820e847
Introduces port validation check and testing frameworks for non-digit port serializations
Commit: 9f4c943
Consolidates isPort regex validator inside lib/utils.js and recomposeAuthority module
Commit: 506b155
Fixes malformed host parsing validation checks involving IP literals with unbalanced brackets
Mitigation Strategies
- Upgrade fast-uri to version 2.4.6, 3.1.7, 4.1.4, or newer depending on the major version track.
- Sanitize client-supplied input for port fields using a strict digits-only regular expression (/^\d*$/) before passing them to URI serialization modules.
Remediation Steps:
- Execute 'npm ls fast-uri' or 'yarn why fast-uri' to inspect the dependency tree and identify vulnerable versions of the package.
- Update package dependencies in package.json to reference safe versions: ^2.4.6, ^3.1.7, or ^4.1.4.
- Apply application-level validation logic to reject port parameters containing structural delimiters such as '@', '/', '?', or '#'.
References
Read the full report for CVE-2026-84292 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)