fastify / fastify/help

CVE-2026-16221 / fast-uri-3.1.2.tgz

Open
#1,125 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
68
Forks
8
Avg merge
11h 2m
Merged PRs (30d)
2

Description

Please see https://www.mend.io/vulnerability-database/CVE-2026-16221/

Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file.As a result, the two parsers extract different hosts from the same input string. **Applications that use fast-uri to enforce host-based policy** such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node's URL or fetch consumers **can be steered to an unintended destination**, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none.

Question: Is there any king of filtering happening in the operations described in the CVE?

Contributor guide

Open the contributing guide

Research direction

Start with the linked CVE and the issue's description of fast-uri versus Node's WHATWG URL parser. No repository files or tests are named; determine whether the operations described perform host-based filtering, then document the finding and applicable fast-uri versions or patches.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.