GHSA-qw65-cvwx-89v3: High severity npm/fast-uri vulnerability

Published Sep 28, 2026
·
Updated

Impact

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, fast-uri escapes the userinfo and host components but concatenates the port verbatim, so a port value that is not a sequence of digits can inject authority delimiters. For example, serializing a component whose port is @127.0.0.1:8124 produces http://trusted.example:@127.0.0.1:8124/app, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it.

This affects applications that build URIs from parts and assign untrusted data to the port component (for example a fixed host from configuration and a port taken from user input or a service record). The same path is reachable through serialize(), normalize(), and equal() in their object forms. A port obtained from parse() is always digits and is not affected.

Patches

This vulnerability has been patched in fast-uri 4.1.4, 3.1.7, and 2.4.6. recomposeAuthority now rejects any port that is not DIGIT per RFC 3986. All users should upgrade.

Workarounds

If upgrading is not immediately possible, validate the port value against the RFC 3986 grammar (digits only) before passing a component to serialize(), normalize(), or equal(), and reject anything else, for example if (!/^\d$/.test(String(port))) throw new Error('invalid port').

Affected Software

3 affected componentsFixes available
npm/fast-uri>=4.0.0<4.1.4
4.1.4
npm/fast-uri>=3.0.0<3.1.7
3.1.7
npm/fast-uri<2.4.6
2.4.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/fast-uri to a version that resolves this vulnerability.

    Fixed in 4.1.4
  2. Upgrade

    Upgrade npm/fast-uri to a version that resolves this vulnerability.

    Fixed in 3.1.7
  3. Upgrade

    Upgrade npm/fast-uri to a version that resolves this vulnerability.

    Fixed in 2.4.6
  4. Upgrade

    Upgrade fast-uri to a version that resolves this vulnerability.

    Fixed in 4.1.4
  5. Upgrade

    Upgrade fast-uri to a version that resolves this vulnerability.

    Fixed in 3.1.7
  6. Upgrade

    Upgrade fast-uri to a version that resolves this vulnerability.

    Fixed in 2.4.6
  7. Configuration

    Before passing an untrusted port to serialize(), normalize(), or equal(), validate it against digits only, for example if (!/^\d*$/.test(String(port))) throw new Error('invalid port'). Reject any other value.

    fast-uri URI components port validation = RFC 3986 *DIGIT (digits only)

Event History

Sep 28, 2026
Advisory Published
via GitHub·09:24 PM
Data Sourced
via GitHub·09:24 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications are affected when they construct a URI from components and place untrusted data in the port field, such as using a configured host with a port supplied by a user or service record. Parsed URIs are not affected because parse() produces a port containing only digits.

2

Can an unauthenticated attacker exploit this remotely?

Yes, where an attacker can control data assigned to the port component of a URI object. The vulnerability requires no privileges or user interaction, but exploitation depends on the application passing attacker-controlled input into that component.

3

Do serialize(), normalize(), and equal() have the same exposure?

Yes. The vulnerable authority recomposition path is reachable through the object forms of serialize(), normalize(), and equal(), not only through direct serialization.

4

What should teams do if they cannot update immediately?

Do not allow untrusted values in URI port components, and validate that every supplied port consists only of digits before constructing, normalizing, comparing, or serializing the URI. Re-parsing or validating the resulting URI is not an effective mitigation because both fast-uri and Node's URL interpret the injected authority as the attacker-controlled host.

5

Which versions contain the fix?

The issue is patched in fast-uri 4.1.4, 3.1.7, and 2.4.6. The patched authority recomposition rejects ports that are not composed entirely of digits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203