CVE-2026-84292
Received Received - Intake

URI Port Injection in fast-uri Library

Vulnerability report for CVE-2026-84292, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: openjs

Description

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-03
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
fastify fast-uri to 2.4.6 (exc)
fastify fast-uri to 3.1.7 (exc)
fastify fast-uri to 4.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper handling of the port component in URI serialization by the fast-uri library. When constructing URIs from parts, untrusted port data can inject authority delimiters, allowing an attacker to redirect the authority to a controlled host while demoting the intended host to userinfo. The issue affects versions before 2.4.6, 3.1.7, and 4.1.4.

Detection Guidance

To detect this vulnerability, check the version of fast-uri in your project dependencies. Run commands like 'npm list fast-uri' or 'yarn list fast-uri' to identify installed versions. If the version is below 2.4.6, 3.1.7, or 4.1.4, the system is vulnerable.

Impact Analysis

This vulnerability can allow an attacker to manipulate URI structures, potentially redirecting requests to malicious hosts. Applications that build URIs from untrusted port inputs are at risk, as the attacker could control the destination of network requests or bypass security controls.

Compliance Impact

This vulnerability primarily impacts data integrity by allowing URI authority manipulation, which could redirect requests to attacker-controlled hosts. While not directly violating GDPR or HIPAA, it may enable unauthorized data access or modification if exploited in systems handling sensitive data, potentially leading to compliance violations depending on context.

Mitigation Strategies

Immediately update fast-uri to version 2.4.6, 3.1.7, or 4.1.4 or later. If updating is not possible, validate the port component against RFC 3986 (digits only) before passing it to serialize, normalize, or equal functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84292. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart