Sep 29, 2026·7 min read·4 visits
Unvalidated port serialization in fast-uri allows remote attackers to perform authority injection and redirect connections to external hosts.
An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.
The library fast-uri is a high-performance URI parser and serializer toolbox compliant with RFC 3986, widely used in Node.js applications such as the Fastify framework. The serialization subsystem translates structured objects containing scheme, host, port, and query properties into valid URI strings. This interface acts as a critical boundary where structured data is serialized for consumption by network clients.
CVE-2026-84292 represents an authority injection vulnerability within the serialization module of fast-uri. The parser fails to validate that the provided port is a strictly numeric sequence before concatenating it onto the reconstituted authority. This allows an attacker to inject special characters, altering the syntactic structure of the final serialized URI.
Standard URI parsers, including Node.js's native URL class and downstream HTTP request clients, parse the malformed serialization result differently. Instead of rejecting the input, they process injected @ symbols as userinfo delimiters. This demotes the original host to userinfo and elevates an attacker-supplied domain as the true target host, bypassing host-based validation filters.
The root cause resides in lib/utils.js within the recomposeAuthority function, which is responsible for building the authority component of the URI. The library implements escaping and validation logic for userinfo and host to prevent injection attacks. However, it handles the port property with a simple type check that accepts both strings and numbers without evaluating their contents.
RFC 3986 Section 3.2.3 strictly defines the port component as a sequence of zero or more decimal digits. By accepting arbitrary strings and concatenating them directly to the authority component, fast-uri deviates from the RFC standard. The unvalidated value is appended verbatim following a colon character, introducing a vector for control character injections.
If the injected string contains an @ symbol, it shifts the boundaries of the parsed URI. According to RFC 3986, the authority string is scanned for an @ character; all text preceding the leftmost @ is interpreted as username and password credentials. Consequently, injecting @attacker.com forces downstream parsers to treat the original legitimate host as a username and the injected domain as the authority host.
A secondary issue relates to malformed bracket handling in hosts. The library assumed that any host starting with [ was a valid IP-literal without validating the terminating ]. This discrepancy allowed attackers to exploit parser differential flaws where unbalanced or misplaced brackets bypassed validation checks, leaving the application vulnerable to connection routing manipulation.
To understand the vulnerability, analyze the original implementation of recomposeAuthority in lib/utils.js. In this block, the function inspects the type of component.port and directly pushes its string representation onto the token buffer if it evaluates to a string or number.
// VULNERABLE (fast-uri < 2.4.6)
if (typeof component.port === 'number' || typeof component.port === 'string') {
uriTokens.push(':')
uriTokens.push(String(component.port)) // String is concatenated verbatim
}// PATCHED (fast-uri >= 2.4.6)
const isPort = RegExp.prototype.test.bind(/^\d*$/u)
if (typeof component.port === 'number' || typeof component.port === 'string') {
const port = String(component.port)
if (!isPort(port)) {
throw new TypeError('URI port is malformed.') // Throws an error for non-digit inputs
}
uriTokens.push(':')
uriTokens.push(port)
}The patch introduces the isPort regular expression-based validator, which restricts the port string to only digit characters using /^\d*$/u. When a non-digit character is detected within the port string, the library throws a TypeError and halts serialization. This prevents the generation of syntactically invalid or malicious URIs entirely, solving the vulnerability at the serialization stage.
Additionally, the patch modifies index.js to harden IP-literal verification. The helper function isIPLiteral is introduced to verify that bracketed hosts strictly start with [ and end with ]. This prevents incomplete bracketed hosts, such as [fe80, from bypassing canonicalization routines and escaping validation steps.
Exploitation of CVE-2026-84292 depends on an application exposing control of the port variable to an external actor during URI reconstruction. This scenario occurs in integrations where application configurations, webhooks, or dynamic API endpoints are built programmatically from client-supplied parameters. Because the library is designed for performance, developers often trust its output without implementing supplementary application-level input validation.
An attacker crafts a payload targeting the port property, containing authority delimiters such as @ or path segment delimiters. If the backend is intended to construct a URI to an internal database or API at http://internal-service.local, sending a port string like @malicious-server.example alters the authority layout. The resulting serialized string becomes http://internal-service.local:@malicious-server.example.
When the application client processes this URI, it interprets internal-service.local: as userinfo and issues the HTTP request directly to malicious-server.example. The attack succeeds silently, as standard parser frameworks do not raise errors during compilation or request execution. This enables the attacker to intercept sensitive authentication tokens, internal request paths, or perform arbitrary outbound API requests.
This attack vector is particularly effective at bypassing whitelist-based URL filters. A security filter that verifies the serialized URI using simple substring lookups (e.g., checking if the string contains internal-service.local) would pass the malformed URL. The vulnerability exploits the structural parsing difference between basic string matching and formal RFC 3986 parsing.
The direct consequence of this vulnerability is the breakdown of integrity in URI serialization. It undermines the trust boundary between the serialization library and the network client. While the CVSS v3.1 score of 7.5 reflects high integrity impact, the practical security risk depends heavily on the execution environment.
If the serialized URIs are forwarded to internal HTTP clients, the vulnerability is a highly reliable vector for Server-Side Request Forgery (SSRF). Attackers can access internal services, compromise metadata endpoints in cloud environments, or query restricted internal administration portals.
The flaw can also be used to execute open redirects or bypass domain-based security boundaries in OAuth configurations, single sign-on flows, or safe-origin checks. Since fast-uri serves as a core dependency within Fastify and other Node.js routing frameworks, the potential exposure across downstream packages is significant.
Currently, the exploit maturity is categorized as proof-of-concept. No functional, weaponized exploit code is observed in the wild. The EPSS score remains low at 0.0038, which represents a minimal probability of automated scanning or bulk exploitation at this stage, but the vulnerability warrants proactive remediation given its critical structural implications.
The primary and most effective remediation strategy is to upgrade fast-uri to the patched versions. For environments running the 2.x branch, update to 2.4.6. For 3.x deployments, upgrade to 3.1.7. For 4.x deployments, transition to 4.1.4. These versions enforce correct RFC 3986 validation rules within the recomposeAuthority component.
If an immediate dependency upgrade is blocked, implementing application-level input sanitization is necessary. Applications should run a strict regular expression validation on all user-supplied port variables before passing them to the URI reconstruction context. The validator must ensure the input consists exclusively of ASCII digit characters.
Implement defense-in-depth measures at the network level to mitigate downstream SSRF risks. Restrict outbound network access from sensitive application servers using egress firewall rules or security groups. Furthermore, configure internal HTTP clients to reject requests pointing to loopback addresses, local private subnets (RFC 1918), or cloud metadata services unless explicitly required by design.
Finally, ensure development workflows utilize software composition analysis (SCA) tooling. Continuous scanning of the Node.js package dependency graph will flag outdated versions of fast-uri or indirect occurrences resolved via transitively imported libraries. This ensures that the vulnerability is identified and mitigated across all codebases in the enterprise.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
fast-uri OpenJS Foundation | < 2.4.6 | 2.4.6 |
fast-uri OpenJS Foundation | >= 3.0.0 < 3.1.7 | 3.1.7 |
fast-uri OpenJS Foundation | >= 4.0.0 < 4.1.4 | 4.1.4 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-116 |
| Attack Vector | Network |
| CVSS Score | 7.5 (High) |
| EPSS Score | 0.0038 |
| Impact | Integrity |
| Exploit Status | poc |
| KEV Status | Not Listed |
The software does not sanitize or escape output correctly, allowing attackers to inject structural delimiters that alter the interpretation of the output.
A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.
A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.
A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.
An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.
CVE-2026-87859 is a medium-severity log injection vulnerability in the Node.js morgan HTTP request logger middleware. Prior to version 1.12.1, the internal sanitization utility fails to escape double-quote characters within logged fields, enabling unauthenticated remote attackers to inject arbitrary text, close log fields early, and spoof critical metadata in downstream log parsers.
An uncontrolled resource consumption vulnerability exists in the multer middleware for Node.js (versions 2.2.0 through 2.3.0) when handling aborted multipart uploads using disk storage. Due to an asynchronous race condition in path resolution, files can become permanently orphaned on disk, leading to storage exhaustion and denial of service.