CVE-2026-75931Disclosure(openjsf / fast-uri)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openjsf fast-uri systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-uri

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
fast-uri

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-24: 3Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-24: 308-24
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75931 fast-uri Host Confusion Vulnerability Enables Policy Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75931

    Post summary

    The text discloses CVE-2026-75931 as a fast-uri Host Confusion vulnerability that can bypass policies, with a link to further details.

    00000132
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-75931 fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as… https://www.cve.org/CVERecord?id=CVE-2026-75931

    Post summary

    The post describes how fast-uri mishandles scheme‑relative URLs during host canonicalization, providing technical detail but no PoC, exploit, mitigation or evidence of active exploitation.

    00000876
    58.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in fast-uri 2.4.5, 3.1.6, and 4.1.3 just released! Patches CVE-2026-75931. Host confusion via skipped IDN canonicalization on scheme-relative references. https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8

    Post summary

    A security fix for CVE-2026-75931 affecting fast-uri has been released, addressing a host confusion bug involving IDN canonicalization.

    00000193
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsffast-uri-node.js-

Explore more