CVE-2026-84394: Host Confusion and SSRF Bypass via Parser Discrepancy in fast-uri
Vulnerability ID: CVE-2026-84394
CVSS Score: 7.5
Published: 2026-09-28
An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.
TL;DR
Malformed URLs with unbalanced brackets bypass fast-uri checks but resolve to internal hosts in WHATWG HTTP clients, enabling SSRF.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-436
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- EPSS Score: 0.0038
- Exploit Status: Proof of Concept (PoC) available
- KEV Status: Not listed
Affected Systems
- fast-uri npm library
-
fast-uri: 2.4.5 (Fixed in:
2.4.6) -
fast-uri: 3.1.6 (Fixed in:
3.1.7) -
fast-uri: 4.1.3 (Fixed in:
4.1.4)
Mitigation Strategies
- Upgrade fast-uri to safe versions (2.4.6, 3.1.7, 4.1.4)
- Align the validation parser with the request execution engine
- Perform pre-flight DNS checks and direct IP verification
Remediation Steps:
- Identify all dependency paths involving fast-uri.
- Explicitly update fast-uri inside package.json dependencies, overrides, or resolutions.
- Run the package manager update script to implement the secure release.
- Redesign security validators to use WHATWG URL API instead of fast-uri.
References
- GitHub Security Advisory GHSA-58mr-gqgx-xq4g
- OpenJS Foundation Advisory Portal
- NVD Vulnerability Details
- CVE Record on CVE.org
Read the full report for CVE-2026-84394 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)