DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-84292: CVE-2026-84292: Authority Injection in fast-uri via Unvalidated Port Component

CVE-2026-84292: Authority Injection in fast-uri via Unvalidated Port Component

Vulnerability ID: CVE-2026-84292
CVSS Score: 7.5
Published: 2026-09-28

An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.

TL;DR

Unvalidated port serialization in fast-uri allows remote attackers to perform authority injection and redirect connections to external hosts.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-116
  • Attack Vector: Network
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.0038
  • Impact: Integrity
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • fast-uri
  • fast-uri: < 2.4.6 (Fixed in: 2.4.6)
  • fast-uri: >= 3.0.0 < 3.1.7 (Fixed in: 3.1.7)
  • fast-uri: >= 4.0.0 < 4.1.4 (Fixed in: 4.1.4)

Code Analysis

Commit: 820e847

Introduces port validation check and testing frameworks for non-digit port serializations

Commit: 9f4c943

Consolidates isPort regex validator inside lib/utils.js and recomposeAuthority module

Commit: 506b155

Fixes malformed host parsing validation checks involving IP literals with unbalanced brackets

Mitigation Strategies

  • Upgrade fast-uri to version 2.4.6, 3.1.7, 4.1.4, or newer depending on the major version track.
  • Sanitize client-supplied input for port fields using a strict digits-only regular expression (/^\d*$/) before passing them to URI serialization modules.

Remediation Steps:

  1. Execute 'npm ls fast-uri' or 'yarn why fast-uri' to inspect the dependency tree and identify vulnerable versions of the package.
  2. Update package dependencies in package.json to reference safe versions: ^2.4.6, ^3.1.7, or ^4.1.4.
  3. Apply application-level validation logic to reject port parameters containing structural delimiters such as '@', '/', '?', or '#'.

References


Read the full report for CVE-2026-84292 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)