<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:openjsf:fast-Uri:4.1.3:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aopenjsffast-uri4.1.3node.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 22:15:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aopenjsffast-uri4.1.3node.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Host Confusion Vulnerability in fast-uri via Malformed URI Authority</title><link>https://feed.craftedsignal.io/briefs/2026-09-fast-uri-host-confusion/</link><pubDate>Mon, 28 Sep 2026 22:15:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-fast-uri-host-confusion/</guid><description>The fast-uri library incorrectly parses URI authorities containing unbalanced brackets, allowing attackers to bypass SSRF denylists and security filters by causing a discrepancy between the parsed host and the host resolved by underlying HTTP clients.</description><content:encoded><![CDATA[<p>The fast-uri library (versions &lt; 2.4.6, &lt; 3.1.7, and &lt; 4.1.4) contains a host confusion vulnerability identified as CVE-2026-84394. The library fails to properly validate the authority section of a URI when it contains unbalanced or misplaced brackets (e.g., <code>[</code> or <code>]</code>). Specifically, if a host string starts with <code>[</code> but does not contain a valid IPv6 literal, <code>fast-uri</code> treats it as a standard host string without triggering an error.</p>
<p>This behavior is dangerous for applications using <code>fast-uri</code> to parse URLs for security decisions, such as SSRF denylists, redirect allowlists, or proxy routing. Because the library incorrectly identifies the host, a security policy may be evaluated against a malformed string while the final network request, performed by downstream libraries like <code>axios</code>, <code>got</code>, or Node.js's <code>http.get</code>, resolves the URI differently. This allows an attacker to route requests to restricted internal IP addresses or domains that the application intended to block.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the bypass of security controls relying on <code>fast-uri</code> for URL validation. This can lead to Server-Side Request Forgery (SSRF) in applications that perform outgoing HTTP requests based on user-supplied URLs. Any web application or proxy service using these versions of <code>fast-uri</code> to make security decisions regarding URL reachability or internal resource access is at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for security teams:</p>
<ul>
<li>Upgrade <code>fast-uri</code> to versions 4.1.4, 3.1.7, or 2.4.6 immediately to implement strict validation of URI host brackets.</li>
<li>If upgrading is not possible, implement a secondary validation layer in your application that rejects any URL where the host contains <code>[</code> or <code>]</code> characters unless the entire host string matches the formal definition of an IPv6 literal (i.e., enclosed in brackets and containing valid IPv6 syntax).</li>
<li>Review application logic that uses <code>fast-uri.parse().host</code> to make authorization or routing decisions to ensure the parsed host matches the intended destination.</li>
<li>Audit logs for instances where external URL parameters include unexpected bracket characters, which may indicate exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>ssrf</category><category>web-security</category></item></channel></rss>