{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fast-uri-v2.3.1--v--2.4.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75975"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fast-uri (2.3.1 - 2.4.4)","fast-uri (3.0.0 - 3.1.5)","fast-uri (4.0.0 - 4.1.2)","fast-uri (v2.3.1 \u003c= v \u003c 2.4.5)","fast-uri (v3.0.0 \u003c= v \u003c 3.1.6)","fast-uri (v4.0.0 \u003c= v \u003c 4.1.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe fast-uri library (versions 2.3.1 through 4.1.3) fails to properly validate the full RFC 3986 grammar for bracketed IPv6 address literals. When the library encounters a malformed IPv6 literal containing invalid trailing text, it incorrectly truncates the input and returns a valid IPv6 address without flagging an error. For example, inputs like \u003ccode\u003e[::not-valid]\u003c/code\u003e are normalized to \u003ccode\u003e[::]\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThis behavior creates a Server-Side Request Forgery (SSRF) risk. Applications that rely on fast-uri to normalize user-provided URLs before performing server-side host-policy checks or outbound requests may inadvertently route traffic to internal, private, or loopback IPv6 addresses. Because the library does not set the 'error' property on the parsed result for these malformed inputs, applications that rely on standard error checking will fail to detect the malformation, effectively bypassing security controls that were intended to prevent access to sensitive internal infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to perform SSRF attacks against internal network resources. By supplying a URL containing a crafted IPv6 host, an attacker can coerce a vulnerable application into performing requests to private or loopback IPv6 addresses that would otherwise be blocked by an allowlist or security middleware. This can lead to unauthorized access to internal administrative interfaces, local services, or sensitive metadata endpoints. The impact is significant for applications that process user-controlled URLs and handle sensitive internal data or administrative tasks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade fast-uri to versions 2.4.5, 3.1.6, or 4.1.3 to remediate CVE-2026-75975, which introduces proper rejection of malformed IPv6 literals.\u003c/li\u003e\n\u003cli\u003eImplement a secondary validation layer that rejects or strips user-supplied URLs containing bracketed IPv6 literals if the application does not explicitly require them.\u003c/li\u003e\n\u003cli\u003eConfigure outbound request handlers to validate hostnames against an explicit, trusted allowlist of IP addresses or FQDNs before initiating the network connection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:04:36Z","date_published":"2026-09-03T00:04:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fast-uri-ssrf/","summary":"The fast-uri library incorrectly normalizes malformed IPv6 bracketed literals, allowing attackers to bypass host-based security checks via SSRF.","title":"SSRF Vulnerability via IPv6 Normalization in fast-uri","url":"https://feed.craftedsignal.io/briefs/2026-09-fast-uri-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Fast-Uri (V2.3.1 \u003c= v \u003c 2.4.5)","version":"https://jsonfeed.org/version/1.1"}