GHSA-qw65-cvwx-89v3: High severity npm/fast-uri vulnerability
Impact
fast-uri serializes the port component of a URI without validating it. When recomposing the authority, fast-uri escapes the userinfo and host components but concatenates the port verbatim, so a port value that is not a sequence of digits can inject authority delimiters. For example, serializing a component whose port is @127.0.0.1:8124 produces http://trusted.example:@127.0.0.1:8124/app, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it.
This affects applications that build URIs from parts and assign untrusted data to the port component (for example a fixed host from configuration and a port taken from user input or a service record). The same path is reachable through serialize(), normalize(), and equal() in their object forms. A port obtained from parse() is always digits and is not affected.
Patches
This vulnerability has been patched in fast-uri 4.1.4, 3.1.7, and 2.4.6. recomposeAuthority now rejects any port that is not DIGIT per RFC 3986. All users should upgrade.
Workarounds
If upgrading is not immediately possible, validate the port value against the RFC 3986 grammar (digits only) before passing a component to serialize(), normalize(), or equal(), and reject anything else, for example if (!/^\d$/.test(String(port))) throw new Error('invalid port').
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/fast-urito a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
npm/fast-urito a version that resolves this vulnerability.Fixed in 3.1.7 - Upgrade
Upgrade
npm/fast-urito a version that resolves this vulnerability.Fixed in 2.4.6 - Upgrade
Upgrade
fast-urito a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
fast-urito a version that resolves this vulnerability.Fixed in 3.1.7 - Upgrade
Upgrade
fast-urito a version that resolves this vulnerability.Fixed in 2.4.6 - Configuration
Before passing an untrusted port to serialize(), normalize(), or equal(), validate it against digits only, for example if (!/^\d*$/.test(String(port))) throw new Error('invalid port'). Reject any other value.
fast-uri URI components port validation = RFC 3986 *DIGIT (digits only)
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications are affected when they construct a URI from components and place untrusted data in the port field, such as using a configured host with a port supplied by a user or service record. Parsed URIs are not affected because parse() produces a port containing only digits.
Can an unauthenticated attacker exploit this remotely?
Yes, where an attacker can control data assigned to the port component of a URI object. The vulnerability requires no privileges or user interaction, but exploitation depends on the application passing attacker-controlled input into that component.
Do serialize(), normalize(), and equal() have the same exposure?
Yes. The vulnerable authority recomposition path is reachable through the object forms of serialize(), normalize(), and equal(), not only through direct serialization.
What should teams do if they cannot update immediately?
Do not allow untrusted values in URI port components, and validate that every supplied port consists only of digits before constructing, normalizing, comparing, or serializing the URI. Re-parsing or validating the resulting URI is not an effective mitigation because both fast-uri and Node's URL interpret the injected authority as the attacker-controlled host.
Which versions contain the fix?
The issue is patched in fast-uri 4.1.4, 3.1.7, and 2.4.6. The patched authority recomposition rejects ports that are not composed entirely of digits.