DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-84394: CVE-2026-84394: Host Confusion and SSRF Bypass via Parser Discrepancy in fast-uri

CVE-2026-84394: Host Confusion and SSRF Bypass via Parser Discrepancy in fast-uri

Vulnerability ID: CVE-2026-84394
CVSS Score: 7.5
Published: 2026-09-28

An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.

TL;DR

Malformed URLs with unbalanced brackets bypass fast-uri checks but resolve to internal hosts in WHATWG HTTP clients, enabling SSRF.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-436
  • Attack Vector: Network
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.0038
  • Exploit Status: Proof of Concept (PoC) available
  • KEV Status: Not listed

Affected Systems

  • fast-uri npm library
  • fast-uri: 2.4.5 (Fixed in: 2.4.6)
  • fast-uri: 3.1.6 (Fixed in: 3.1.7)
  • fast-uri: 4.1.3 (Fixed in: 4.1.4)

Mitigation Strategies

  • Upgrade fast-uri to safe versions (2.4.6, 3.1.7, 4.1.4)
  • Align the validation parser with the request execution engine
  • Perform pre-flight DNS checks and direct IP verification

Remediation Steps:

  1. Identify all dependency paths involving fast-uri.
  2. Explicitly update fast-uri inside package.json dependencies, overrides, or resolutions.
  3. Run the package manager update script to implement the secure release.
  4. Redesign security validators to use WHATWG URL API instead of fast-uri.

References


Read the full report for CVE-2026-84394 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)