Description
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
Published: 2026-08-24
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

fast-uri’s IPv6 parsing flaw allows an attacker to supply a malformed bracketed literal that the parser normalizes into a private or unspecified IPv6 address without signaling an error. This silent rewrite means an application that feeds fast-uri‑parsed values to outbound HTTP clients can be redirected to internal or local services, providing a server‑side request forgery and address‑policy bypass. The weakness is an input validation error (CWE‑20) that leads directly to SSRF (CWE‑918).

Affected Systems

This issue impacts the fast-uri URI parser for Node.js library versions 2.3.1 through 2.4.4, 3.0.0 through 3.1.5, and 4.0.0 through 4.1.2 in any Node.js application that uses fast-uri to validate or normalize URLs before outbound requests, redirects, proxy configurations, or address‑policy enforcement.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5 and is not listed in CISA KEV. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of an error on parsing makes detection difficult. An attacker who controls the input fed to fast-uri—such as a user‑supplied link, a redirect target, or a proxy header—can induce the server to connect to a private‑range or localhost IPv6 address, enabling data exfiltration or internal service hijacking with no authentication requirement. The impact is therefore significant if the application trusts fast-uri‑parsed URLs for outbound traffic.

Generated by OpenCVE AI on August 24, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade fast-uri to the latest patched versions (2.4.5, 3.1.6, or 4.1.3 or newer).
  • If an immediate upgrade is not possible, apply a pre‑processing filter that rejects bracketed IPv6 literals containing trailing characters or otherwise validates the full IPv6 grammar before passing the string to fast-uri.
  • Implement an application‑level check that rejects localhost or private IP addresses resolved from any parsed URL, thereby preventing unintended internal connections.

Generated by OpenCVE AI on August 24, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Fast-uri
Fast-uri fast-uri
Vendors & Products Fast-uri
Fast-uri fast-uri

Mon, 24 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
Title fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
Weaknesses CWE-20
CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Fast-uri Fast-uri
cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-08-24T09:58:07.698Z

Reserved: 2026-08-18T18:09:48.366Z

Link: CVE-2026-75975

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T10:16:40.237

Modified: 2026-08-24T10:16:40.237

Link: CVE-2026-75975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T11:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-918

    Server-Side Request Forgery (SSRF)