Description
fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference such as //host there is no scheme, so the host canonicalization that would normally repair this does not run, and parse, normalize, and equal then disagree on the same host. An application that makes a case-sensitive host decision on fast-uri output, for example a host allowlist or denylist that compares the parsed host or uses equal, can be steered past the check with a percent-encoded uppercase octet, and because hostnames are case-insensitive in DNS and HTTP the evading spelling still reaches the host the check meant to gate. The issue is fixed in fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of those versions or later. As a workaround, compare hosts case-insensitively by lowercasing the parsed host before any allowlist or denylist decision.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Host validation bypass
Action: Immediate Patch
AI Analysis

Impact

fast‑uri, a Node.js URI parser used by Fastify and the ajv JSON schema validator, incorrectly normalizes the host component in certain releases. The parser folds the host to lowercase before percent‑decoding, so percent‑encoded uppercase octets such as %41 resolve to a literal "A" that remains unlowercased. On scheme‑relative references, where no scheme is supplied, the normal host canonicalization step is skipped, resulting in a parsed host that may contain mixed‑case characters. Applications that compare the parsed host case‑sensitively – for example, through an allowlist or denylist – can thus be tricked into accepting otherwise disallowed hosts. Because hostnames in DNS and HTTP are case‑insensitive, the attacker can reach the intended target while bypassing the check, enabling host header injection or domain impersonation.

Affected Systems

The bug is present in fast‑uri library versions prior to 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4. The issue is fixed in fast‑uri 2.4.7, 3.1.8, and 4.1.5, and later releases. The library is widely used by the Fastify web framework and the ajv JSON schema validator.

Risk and Exploitability

This vulnerability has a CVSS score of 4.8, classifying it as medium severity. The EPSS score is less than 1%, indicating a low probability of exploitation. It is not currently listed by CISA as a known exploited vulnerability. The likely attack vector involves an application that performs case‑sensitive host validation on values produced by fast‑uri, such as a whitelist check. An attacker crafts a URI containing percent‑encoded uppercase octets to bypass the check, and the canonicalized host still resolves to the intended domain, potentially allowing host header injection or redirect to malicious hosts.

Generated by OpenCVE AI on September 17, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade fast‑uri to v2.4.7, v3.1.8, v4.1.5, or a later release.
  • Update dependent frameworks such as Fastify and ajv to versions that incorporate the fixed fast‑uri library.
  • Until a patch is applied, modify host validation logic to perform case‑insensitive comparisons by lowercasing the parsed host before checking against allowlists or denylists.
  • Audit your application for any other case‑sensitive host comparisons that could be similarly compromised.
  • Avoid accepting scheme‑relative references or reject URIs that contain percent‑encoded uppercase octets when a host whitelist is enforced.

Generated by OpenCVE AI on September 17, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hrr3-gc8f-f4qj fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Fast-uri
Fast-uri fast-uri
Vendors & Products Fast-uri
Fast-uri fast-uri

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference such as //host there is no scheme, so the host canonicalization that would normally repair this does not run, and parse, normalize, and equal then disagree on the same host. An application that makes a case-sensitive host decision on fast-uri output, for example a host allowlist or denylist that compares the parsed host or uses equal, can be steered past the check with a percent-encoded uppercase octet, and because hostnames are case-insensitive in DNS and HTTP the evading spelling still reaches the host the check meant to gate. The issue is fixed in fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of those versions or later. As a workaround, compare hosts case-insensitively by lowercasing the parsed host before any allowlist or denylist decision.
Title fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
Weaknesses CWE-178
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Fast-uri Fast-uri
cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-15T12:35:44.789Z

Reserved: 2026-09-07T15:02:14.920Z

Link: CVE-2026-86472

cve-icon Vulnrichment

Updated: 2026-09-15T12:35:33.623Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T11:17:12.327

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-86472

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T10:29:50Z

Links: CVE-2026-86472 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity