DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-86472: CVE-2026-86472: Hostname Canonicalization Bypass in fast-uri via Scheme-Relative URLs

CVE-2026-86472: Hostname Canonicalization Bypass in fast-uri via Scheme-Relative URLs

Vulnerability ID: CVE-2026-86472
CVSS Score: 4.8
Published: 2026-09-29

CVE-2026-86472 is a validation bypass vulnerability in fast-uri (a high-performance RFC 3986 URI toolbox heavily used by popular Node.js frameworks like Fastify and validation libraries like AJV). The vulnerability stems from improper handling of case sensitivity (CWE-178) due to an incorrect order of operations during hostname canonicalization in scheme-relative URLs. An attacker can leverage percent-encoded uppercase characters within scheme-relative URLs to bypass domain blocklists/allowlists in downstream applications. Because hostname resolution in DNS and HTTP is case-insensitive, the bypassed host representation still routes to the target destination, resulting in potential Server-Side Request Forgery (SSRF) or security control bypasses.

TL;DR

An incorrect sequence of case folding and percent-decoding in fast-uri allows attackers to bypass case-sensitive domain filters using percent-encoded uppercase hostnames in scheme-relative URLs.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-178
  • Attack Vector: Network (AV:N)
  • CVSS Score: 4.8
  • EPSS Score: 0.00253
  • Exploit Status: poc
  • CISA KEV Status: Not Listed

Affected Systems

  • fast-uri < 2.4.7
  • fast-uri 3.x < 3.1.8
  • fast-uri 4.x < 4.1.5
  • fast-uri: < 2.4.7 (Fixed in: 2.4.7)
  • fast-uri: 3.0.0 - 3.1.7 (Fixed in: 3.1.8)
  • fast-uri: 4.0.0 - 4.1.4 (Fixed in: 4.1.5)

Code Analysis

Commit: 5dabb86

fix: normalize host correctly in scheme-relative URIs

Commit: c88b59e

fix: ensure host percent decoding occurs before folding case

Mitigation Strategies

  • Upgrade fast-uri dependency to patched versions.
  • Enforce manual lowercasing on all parsed hostname outputs before comparison.
  • Deploy Web Application Firewall rules to detect and drop scheme-relative URLs with percent-encoded characters.

Remediation Steps:

  1. Check project dependency tree for fast-uri versions using npm ls fast-uri.
  2. Apply package overrides or resolutions in package.json to force safe versions.
  3. Run npm install or yarn install to update lockfiles with patched versions (2.4.7, 3.1.8, or 4.1.5).
  4. Verify parsed output normalization by adding test cases for '//%41.com' in the integration suite.

References


Read the full report for CVE-2026-86472 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)