CVE-2026-86818: Mailto Header Injection via Percent-Encoded Field-Name Desynchronization in fast-uri
Vulnerability ID: CVE-2026-86818
CVSS Score: 4.8
Published: 2026-09-29
A security-critical desynchronization vulnerability exists in fast-uri versions 4.1.3 and 4.1.4. Due to incorrect order-of-operations, the mailto scheme parser validates raw percent-encoded parameter keys instead of normalized keys, but subsequently decodes and writes them into a generic headers object. When the parsed URI is serialized, these keys are re-emitted literally, allowing attackers to bypass validation boundaries and smuggle unauthorized recipients, subjects, or body parameters in downstream mailing applications.
TL;DR
A validation discrepancy in fast-uri allows remote attackers to smuggle mailto parameters such as 'to', 'subject', and 'body' by using percent-encoded names like '%74o', bypassing safety validations before serialization.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-172 / CWE-436
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 4.8
- Exploitability Subscore: 2.2
- Impact Subscore: 2.5
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- fast-uri versions 4.1.3 and 4.1.4
- Node.js applications parsing mailto schemas with fast-uri
- Downstream packages containing transient dependencies on fast-uri v4.1.3/v4.1.4, including Fastify and ajv
-
fast-uri: >= 4.1.3, <= 4.1.4 (Fixed in:
4.1.5)
Code Analysis
Commit: f40a88f
Ensure mailto parameter names are decoded and lower-cased prior to parsing, and implement header canonicalization in serialization
Commit: 5dabb86
Implement structural normalization updates for mailto parameter logic
Commit: a071da6
Tag and release version 4.1.5 containing the vulnerability fix
Exploit Details
- GitHub Advisory: Details on reproducing the parser desynchronization using percent-encoded parameters
Mitigation Strategies
- Upgrade fast-uri dependency to version 4.1.5 or newer
- Enforce dependency overrides or resolutions in package.json to update transitive fast-uri instances in Fastify and ajv
- Implement a pre-serialization filter that manually purges reserved keys from parsed.headers
Remediation Steps:
- Scan the project node_modules using 'npm ls fast-uri' to identify vulnerable versions
- Add overrides for fast-uri version 4.1.5 inside the project package.json file
- Re-generate the lockfile using 'npm install' or 'yarn install' to apply the resolution
- Verify that validation logic parses and serializes mailto links correctly using the updated package
References
- GHSA-jvvf-x445-j334: mailto header/parameter injection via percent-encoded field-name desynchronization
- NVD - CVE-2026-86818 Detail
- CVE.org Record - CVE-2026-86818
- OpenJS Foundation Security Advisories
- fast-uri Release v4.1.5
- Wiz Vulnerability Database: CVE-2026-86818
Read the full report for CVE-2026-86818 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)