Description
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
Published: 2026-08-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery
Action: Patch Immediately
AI Analysis

Impact

fast-uri’s IPv6 parsing flaw allows an attacker to supply a malformed bracketed literal that the parser normalizes into a private or unspecified IPv6 address without signaling an error. This silent rewrite means an application that feeds fast-uri‑parsed values to outbound HTTP clients can be redirected to internal or local services, providing a server‑side request forgery and address‑policy bypass. The weakness is an input validation error (CWE‑20) that leads directly to SSRF (CWE‑918).

Affected Systems

This issue impacts the fast-uri URI parser for Node.js library versions 2.3.1 through 2.4.4, 3.0.0 through 3.1.5, and 4.0.0 through 4.1.2 in any Node.js application that uses fast-uri to validate or normalize URLs before outbound requests, redirects, proxy configurations, or address‑policy enforcement.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5 and is not listed in CISA KEV. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of an error on parsing makes detection difficult. An attacker who controls the input fed to fast-uri—such as a user‑supplied link, a redirect target, or a proxy header—can induce the server to connect to a private‑range or localhost IPv6 address, enabling data exfiltration or internal service hijacking with no authentication requirement. The impact is therefore significant if the application trusts fast-uri‑parsed URLs for outbound traffic.

Generated by OpenCVE AI on August 24, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade fast-uri to the latest patched versions (2.4.5, 3.1.6, or 4.1.3 or newer).
  • If an immediate upgrade is not possible, apply a pre‑processing filter that rejects bracketed IPv6 literals containing trailing characters or otherwise validates the full IPv6 grammar before passing the string to fast-uri.
  • Implement an application‑level check that rejects localhost or private IP addresses resolved from any parsed URL, thereby preventing unintended internal connections.

Generated by OpenCVE AI on August 24, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f65p-4m7j-42xc fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Openjsf
Openjsf fast-uri
CPEs cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*
Vendors & Products Openjsf
Openjsf fast-uri

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Fast-uri
Fast-uri fast-uri
Vendors & Products Fast-uri
Fast-uri fast-uri

Mon, 24 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
Title fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
Weaknesses CWE-20
CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Fast-uri Fast-uri
Openjsf Fast-uri
cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-08-24T14:30:09.105Z

Reserved: 2026-08-18T18:09:48.366Z

Link: CVE-2026-75975

cve-icon Vulnrichment

Updated: 2026-08-24T14:30:03.563Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-24T10:16:40.237

Modified: 2026-09-02T14:44:17.457

Link: CVE-2026-75975

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-24T09:58:07Z

Links: CVE-2026-75975 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T11:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-918

    Server-Side Request Forgery (SSRF)