CVE-2026-75899Patch(openjsf / fast-uri)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openjsf fast-uri systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a server-side request forgery and host-policy bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded percent signs. Users should upgrade to a patched version.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-174CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-uri

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
fast-uri

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-24: 3Patch / Workaround · 2026-08-24: 2Technical Details · 2026-08-24: 308-24
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • HOL@HashgraphOnline
    Patch

    Your host allowlist can clear a URL that still ends up on localhost. Nested encoding in the hostname survives the first decode. Upgrade fast-uri to 4.1.3 (or 3.1.6 / 2.4.5). CVE-2026-75899. https://hol.org/blog/cve-2026-75899-fast-uri-ssrf-repeated-hostname-decoding https://t.co/A6kBKcRHv0

    Post summary

    The post warns that fast‑uri’s SSRF flaw (CVE‑2026‑75899) can bypass host allowlists via repeated hostname decoding, and recommends upgrading to version 4.1.3 (or the earlier patched releases 3.1.6 / 2.4.5).

    0401011.1K
    19.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-75899 fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority reco… https://www.cve.org/CVERecord?id=CVE-2026-75899

    Post summary

    The post briefly describes CVE-2026-75899 as a double-decoding flaw in fast-uri, without any PoC, exploit, patch, or indication of active exploitation.

    000001.4K
    58.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in fast-uri 2.4.5, 3.1.6, and 4.1.3 just released! Patches CVE-2026-75899. Server-side request forgery via repeated hostname percent-decoding. https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf

    Post summary

    This post announces a high‑severity patch for CVE‑2026‑75899, fixing an SSRF issue caused by repeated hostname percent‑decoding, and identifies the new patch versions available.

    00000205
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsffast-uri-node.js-

Explore more