CVE-2026-75975Disclosure(openjsf / fast-uri)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openjsf fast-uri systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-uri

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
fast-uri

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-24: 3Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-24: 208-24
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-75975 fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an author… https://www.cve.org/CVERecord?id=CVE-2026-75975

    Post summary

    CVE-2026-75975 impacts fast-uri’s bracketed IPv6 parsing logic, which fails to validate the full IPv6 grammar and permits malformed trailing text; no PoC, exploit, active exploitation, or patch information is provided.

    000101.5K
    58.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in fast-uri 2.4.5, 3.1.6, and 4.1.3 just released! Patches CVE-2026-75975. Server-side request forgery via malformed IPv6 normalization. https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc

    Post summary

    The announcement highlights the release of a high‑severity patch for fast‑uri library versions, addressing CVE-2026-75975, a server‑side request forgery vulnerability involving malformed IPv6 normalization.

    00010204
    5.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-75975 fast-uri URI Parser Vulnerability Enables Server-Side Request For... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75975 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet cites CVE‑2026‑75975 and links to a general vulnerability detail page but provides no additional technical, exploit, or mitigation information.

    00000103
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsffast-uri-node.js-

Explore more