{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenjsffast-uri2.4.5node.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openjsf:fast-uri:2.4.5:*:*:*:*:node.js:*:*","cpe:2.3:a:openjsf:fast-uri:3.1.6:*:*:*:*:node.js:*:*","cpe:2.3:a:openjsf:fast-uri:4.1.3:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-84394"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fast-uri (\u003c 4.1.4, \u003c 3.1.7, \u003c 2.4.6)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ssrf","web-security"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe fast-uri library (versions \u0026lt; 2.4.6, \u0026lt; 3.1.7, and \u0026lt; 4.1.4) contains a host confusion vulnerability identified as CVE-2026-84394. The library fails to properly validate the authority section of a URI when it contains unbalanced or misplaced brackets (e.g., \u003ccode\u003e[\u003c/code\u003e or \u003ccode\u003e]\u003c/code\u003e). Specifically, if a host string starts with \u003ccode\u003e[\u003c/code\u003e but does not contain a valid IPv6 literal, \u003ccode\u003efast-uri\u003c/code\u003e treats it as a standard host string without triggering an error.\u003c/p\u003e\n\u003cp\u003eThis behavior is dangerous for applications using \u003ccode\u003efast-uri\u003c/code\u003e to parse URLs for security decisions, such as SSRF denylists, redirect allowlists, or proxy routing. Because the library incorrectly identifies the host, a security policy may be evaluated against a malformed string while the final network request, performed by downstream libraries like \u003ccode\u003eaxios\u003c/code\u003e, \u003ccode\u003egot\u003c/code\u003e, or Node.js's \u003ccode\u003ehttp.get\u003c/code\u003e, resolves the URI differently. This allows an attacker to route requests to restricted internal IP addresses or domains that the application intended to block.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the bypass of security controls relying on \u003ccode\u003efast-uri\u003c/code\u003e for URL validation. This can lead to Server-Side Request Forgery (SSRF) in applications that perform outgoing HTTP requests based on user-supplied URLs. Any web application or proxy service using these versions of \u003ccode\u003efast-uri\u003c/code\u003e to make security decisions regarding URL reachability or internal resource access is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003efast-uri\u003c/code\u003e to versions 4.1.4, 3.1.7, or 2.4.6 immediately to implement strict validation of URI host brackets.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not possible, implement a secondary validation layer in your application that rejects any URL where the host contains \u003ccode\u003e[\u003c/code\u003e or \u003ccode\u003e]\u003c/code\u003e characters unless the entire host string matches the formal definition of an IPv6 literal (i.e., enclosed in brackets and containing valid IPv6 syntax).\u003c/li\u003e\n\u003cli\u003eReview application logic that uses \u003ccode\u003efast-uri.parse().host\u003c/code\u003e to make authorization or routing decisions to ensure the parsed host matches the intended destination.\u003c/li\u003e\n\u003cli\u003eAudit logs for instances where external URL parameters include unexpected bracket characters, which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T22:15:18Z","date_published":"2026-09-28T22:15:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fast-uri-host-confusion/","summary":"The fast-uri library incorrectly parses URI authorities containing unbalanced brackets, allowing attackers to bypass SSRF denylists and security filters by causing a discrepancy between the parsed host and the host resolved by underlying HTTP clients.","title":"Host Confusion Vulnerability in fast-uri via Malformed URI Authority","url":"https://feed.craftedsignal.io/briefs/2026-09-fast-uri-host-confusion/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openjsf:fast-Uri:2.4.5:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}