CVE-2026-86472: Hostname Canonicalization Bypass in fast-uri via Scheme-Relative URLs
Vulnerability ID: CVE-2026-86472
CVSS Score: 4.8
Published: 2026-09-29
CVE-2026-86472 is a validation bypass vulnerability in fast-uri (a high-performance RFC 3986 URI toolbox heavily used by popular Node.js frameworks like Fastify and validation libraries like AJV). The vulnerability stems from improper handling of case sensitivity (CWE-178) due to an incorrect order of operations during hostname canonicalization in scheme-relative URLs. An attacker can leverage percent-encoded uppercase characters within scheme-relative URLs to bypass domain blocklists/allowlists in downstream applications. Because hostname resolution in DNS and HTTP is case-insensitive, the bypassed host representation still routes to the target destination, resulting in potential Server-Side Request Forgery (SSRF) or security control bypasses.
TL;DR
An incorrect sequence of case folding and percent-decoding in fast-uri allows attackers to bypass case-sensitive domain filters using percent-encoded uppercase hostnames in scheme-relative URLs.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-178
- Attack Vector: Network (AV:N)
- CVSS Score: 4.8
- EPSS Score: 0.00253
- Exploit Status: poc
- CISA KEV Status: Not Listed
Affected Systems
- fast-uri < 2.4.7
- fast-uri 3.x < 3.1.8
- fast-uri 4.x < 4.1.5
-
fast-uri: < 2.4.7 (Fixed in:
2.4.7) -
fast-uri: 3.0.0 - 3.1.7 (Fixed in:
3.1.8) -
fast-uri: 4.0.0 - 4.1.4 (Fixed in:
4.1.5)
Code Analysis
Commit: 5dabb86
fix: normalize host correctly in scheme-relative URIs
Commit: c88b59e
fix: ensure host percent decoding occurs before folding case
Mitigation Strategies
- Upgrade fast-uri dependency to patched versions.
- Enforce manual lowercasing on all parsed hostname outputs before comparison.
- Deploy Web Application Firewall rules to detect and drop scheme-relative URLs with percent-encoded characters.
Remediation Steps:
- Check project dependency tree for fast-uri versions using
npm ls fast-uri. - Apply package overrides or resolutions in package.json to force safe versions.
- Run
npm installoryarn installto update lockfiles with patched versions (2.4.7, 3.1.8, or 4.1.5). - Verify parsed output normalization by adding test cases for '//%41.com' in the integration suite.
References
- GitHub Security Advisory GHSA-hrr3-gc8f-f4qj
- OpenJS Foundation Security Advisories
- NVD Entry CVE-2026-86472
- CVE Record CVE-2026-86472
Read the full report for CVE-2026-86472 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)