CVE-2026-16221 / fast-uri-3.1.2.tgz
- Dominant language
- No language data
- Stars
- 68
- Forks
- 8
- Avg merge
- 11h 2m
- Merged PRs (30d)
- 2
Description
Please see https://www.mend.io/vulnerability-database/CVE-2026-16221/
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file.As a result, the two parsers extract different hosts from the same input string. **Applications that use fast-uri to enforce host-based policy** such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node's URL or fetch consumers **can be steered to an unintended destination**, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none.
Question: Is there any king of filtering happening in the operations described in the CVE?
Contributor guide
Research direction
Start with the linked CVE and the issue's description of fast-uri versus Node's WHATWG URL parser. No repository files or tests are named; determine whether the operations described perform host-based filtering, then document the finding and applicable fast-uri versions or patches.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100