Impact
fast‑uri, a Node.js URI parser used by Fastify and the ajv JSON schema validator, incorrectly normalizes the host component in certain releases. The parser folds the host to lowercase before percent‑decoding, so percent‑encoded uppercase octets such as %41 resolve to a literal "A" that remains unlowercased. On scheme‑relative references, where no scheme is supplied, the normal host canonicalization step is skipped, resulting in a parsed host that may contain mixed‑case characters. Applications that compare the parsed host case‑sensitively – for example, through an allowlist or denylist – can thus be tricked into accepting otherwise disallowed hosts. Because hostnames in DNS and HTTP are case‑insensitive, the attacker can reach the intended target while bypassing the check, enabling host header injection or domain impersonation.
Affected Systems
The bug is present in fast‑uri library versions prior to 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4. The issue is fixed in fast‑uri 2.4.7, 3.1.8, and 4.1.5, and later releases. The library is widely used by the Fastify web framework and the ajv JSON schema validator.
Risk and Exploitability
This vulnerability has a CVSS score of 4.8, classifying it as medium severity. The EPSS score is less than 1%, indicating a low probability of exploitation. It is not currently listed by CISA as a known exploited vulnerability. The likely attack vector involves an application that performs case‑sensitive host validation on values produced by fast‑uri, such as a whitelist check. An attacker crafts a URI containing percent‑encoded uppercase octets to bypass the check, and the canonicalized host still resolves to the intended domain, potentially allowing host header injection or redirect to malicious hosts.
OpenCVE Enrichment
Github GHSA