CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-84292

CVE-2026-84292: Authority Injection in fast-uri via Unvalidated Port Component

Amit Schendel
Amit Schendel
Senior Security Researcher

Sep 29, 2026·7 min read·4 visits

Executive Summary (TL;DR)

Unvalidated port serialization in fast-uri allows remote attackers to perform authority injection and redirect connections to external hosts.

An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.

Vulnerability Overview

The library fast-uri is a high-performance URI parser and serializer toolbox compliant with RFC 3986, widely used in Node.js applications such as the Fastify framework. The serialization subsystem translates structured objects containing scheme, host, port, and query properties into valid URI strings. This interface acts as a critical boundary where structured data is serialized for consumption by network clients.

CVE-2026-84292 represents an authority injection vulnerability within the serialization module of fast-uri. The parser fails to validate that the provided port is a strictly numeric sequence before concatenating it onto the reconstituted authority. This allows an attacker to inject special characters, altering the syntactic structure of the final serialized URI.

Standard URI parsers, including Node.js's native URL class and downstream HTTP request clients, parse the malformed serialization result differently. Instead of rejecting the input, they process injected @ symbols as userinfo delimiters. This demotes the original host to userinfo and elevates an attacker-supplied domain as the true target host, bypassing host-based validation filters.

Root Cause Analysis

The root cause resides in lib/utils.js within the recomposeAuthority function, which is responsible for building the authority component of the URI. The library implements escaping and validation logic for userinfo and host to prevent injection attacks. However, it handles the port property with a simple type check that accepts both strings and numbers without evaluating their contents.

RFC 3986 Section 3.2.3 strictly defines the port component as a sequence of zero or more decimal digits. By accepting arbitrary strings and concatenating them directly to the authority component, fast-uri deviates from the RFC standard. The unvalidated value is appended verbatim following a colon character, introducing a vector for control character injections.

If the injected string contains an @ symbol, it shifts the boundaries of the parsed URI. According to RFC 3986, the authority string is scanned for an @ character; all text preceding the leftmost @ is interpreted as username and password credentials. Consequently, injecting @attacker.com forces downstream parsers to treat the original legitimate host as a username and the injected domain as the authority host.

A secondary issue relates to malformed bracket handling in hosts. The library assumed that any host starting with [ was a valid IP-literal without validating the terminating ]. This discrepancy allowed attackers to exploit parser differential flaws where unbalanced or misplaced brackets bypassed validation checks, leaving the application vulnerable to connection routing manipulation.

Code Analysis

To understand the vulnerability, analyze the original implementation of recomposeAuthority in lib/utils.js. In this block, the function inspects the type of component.port and directly pushes its string representation onto the token buffer if it evaluates to a string or number.

// VULNERABLE (fast-uri < 2.4.6)
if (typeof component.port === 'number' || typeof component.port === 'string') {
  uriTokens.push(':')
  uriTokens.push(String(component.port)) // String is concatenated verbatim
}
// PATCHED (fast-uri >= 2.4.6)
const isPort = RegExp.prototype.test.bind(/^\d*$/u)
 
if (typeof component.port === 'number' || typeof component.port === 'string') {
  const port = String(component.port)
  if (!isPort(port)) {
    throw new TypeError('URI port is malformed.') // Throws an error for non-digit inputs
  }
  uriTokens.push(':')
  uriTokens.push(port)
}

The patch introduces the isPort regular expression-based validator, which restricts the port string to only digit characters using /^\d*$/u. When a non-digit character is detected within the port string, the library throws a TypeError and halts serialization. This prevents the generation of syntactically invalid or malicious URIs entirely, solving the vulnerability at the serialization stage.

Additionally, the patch modifies index.js to harden IP-literal verification. The helper function isIPLiteral is introduced to verify that bracketed hosts strictly start with [ and end with ]. This prevents incomplete bracketed hosts, such as [fe80, from bypassing canonicalization routines and escaping validation steps.

Exploitation Methodology

Exploitation of CVE-2026-84292 depends on an application exposing control of the port variable to an external actor during URI reconstruction. This scenario occurs in integrations where application configurations, webhooks, or dynamic API endpoints are built programmatically from client-supplied parameters. Because the library is designed for performance, developers often trust its output without implementing supplementary application-level input validation.

An attacker crafts a payload targeting the port property, containing authority delimiters such as @ or path segment delimiters. If the backend is intended to construct a URI to an internal database or API at http://internal-service.local, sending a port string like @malicious-server.example alters the authority layout. The resulting serialized string becomes http://internal-service.local:@malicious-server.example.

When the application client processes this URI, it interprets internal-service.local: as userinfo and issues the HTTP request directly to malicious-server.example. The attack succeeds silently, as standard parser frameworks do not raise errors during compilation or request execution. This enables the attacker to intercept sensitive authentication tokens, internal request paths, or perform arbitrary outbound API requests.

This attack vector is particularly effective at bypassing whitelist-based URL filters. A security filter that verifies the serialized URI using simple substring lookups (e.g., checking if the string contains internal-service.local) would pass the malformed URL. The vulnerability exploits the structural parsing difference between basic string matching and formal RFC 3986 parsing.

Impact Assessment

The direct consequence of this vulnerability is the breakdown of integrity in URI serialization. It undermines the trust boundary between the serialization library and the network client. While the CVSS v3.1 score of 7.5 reflects high integrity impact, the practical security risk depends heavily on the execution environment.

If the serialized URIs are forwarded to internal HTTP clients, the vulnerability is a highly reliable vector for Server-Side Request Forgery (SSRF). Attackers can access internal services, compromise metadata endpoints in cloud environments, or query restricted internal administration portals.

The flaw can also be used to execute open redirects or bypass domain-based security boundaries in OAuth configurations, single sign-on flows, or safe-origin checks. Since fast-uri serves as a core dependency within Fastify and other Node.js routing frameworks, the potential exposure across downstream packages is significant.

Currently, the exploit maturity is categorized as proof-of-concept. No functional, weaponized exploit code is observed in the wild. The EPSS score remains low at 0.0038, which represents a minimal probability of automated scanning or bulk exploitation at this stage, but the vulnerability warrants proactive remediation given its critical structural implications.

Remediation and Defense-in-Depth

The primary and most effective remediation strategy is to upgrade fast-uri to the patched versions. For environments running the 2.x branch, update to 2.4.6. For 3.x deployments, upgrade to 3.1.7. For 4.x deployments, transition to 4.1.4. These versions enforce correct RFC 3986 validation rules within the recomposeAuthority component.

If an immediate dependency upgrade is blocked, implementing application-level input sanitization is necessary. Applications should run a strict regular expression validation on all user-supplied port variables before passing them to the URI reconstruction context. The validator must ensure the input consists exclusively of ASCII digit characters.

Implement defense-in-depth measures at the network level to mitigate downstream SSRF risks. Restrict outbound network access from sensitive application servers using egress firewall rules or security groups. Furthermore, configure internal HTTP clients to reject requests pointing to loopback addresses, local private subnets (RFC 1918), or cloud metadata services unless explicitly required by design.

Finally, ensure development workflows utilize software composition analysis (SCA) tooling. Continuous scanning of the Node.js package dependency graph will flag outdated versions of fast-uri or indirect occurrences resolved via transitively imported libraries. This ensures that the vulnerability is identified and mitigated across all codebases in the enterprise.

Fix Analysis (3)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Probability
0.38%
Top 71% most exploited

Affected Systems

fast-uri

Affected Versions Detail

Product
Affected Versions
Fixed Version
fast-uri
OpenJS Foundation
< 2.4.62.4.6
fast-uri
OpenJS Foundation
>= 3.0.0 < 3.1.73.1.7
fast-uri
OpenJS Foundation
>= 4.0.0 < 4.1.44.1.4
AttributeDetail
CWE IDCWE-116
Attack VectorNetwork
CVSS Score7.5 (High)
EPSS Score0.0038
ImpactIntegrity
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
CWE-116
Improper Encoding or Escaping of Output

The software does not sanitize or escape output correctly, allowing attackers to inject structural delimiters that alter the interpretation of the output.

References & Sources

  • [1]GitHub Security Advisory GHSA-qw65-cvwx-89v3
  • [2]NVD - CVE-2026-84292

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•18 minutes ago•CVE-2026-88058
8.6

CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.

Alon Barad
Alon Barad
3 views•9 min read
•about 1 hour ago•CVE-2026-101910
6.9

CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.

Alon Barad
Alon Barad
2 views•6 min read
•about 2 hours ago•CVE-2026-101913
6.3

CVE-2026-101913: Link-Local Address Validation Bypass in ip-address Library Enables SSRF

A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.

Alon Barad
Alon Barad
3 views•6 min read
•about 3 hours ago•CVE-2026-84394
7.5

CVE-2026-84394: Host Confusion and SSRF Bypass via Parser Discrepancy in fast-uri

An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.

Alon Barad
Alon Barad
4 views•6 min read
•about 5 hours ago•CVE-2026-87859
5.3

CVE-2026-87859: Log Injection Vulnerability in Morgan HTTP Request Logger

CVE-2026-87859 is a medium-severity log injection vulnerability in the Node.js morgan HTTP request logger middleware. Prior to version 1.12.1, the internal sanitization utility fails to escape double-quote characters within logged fields, enabling unauthenticated remote attackers to inject arbitrary text, close log fields early, and spoof critical metadata in downstream log parsers.

Alon Barad
Alon Barad
5 views•8 min read
•about 7 hours ago•CVE-2026-88932
5.3

CVE-2026-88932: Uncontrolled Resource Consumption (Denial of Service) via orphaned disk writes on aborted uploads in multer

An uncontrolled resource consumption vulnerability exists in the multer middleware for Node.js (versions 2.2.0 through 2.3.0) when handling aborted multipart uploads using disk storage. Due to an asynchronous race condition in path resolution, files can become permanently orphaned on disk, leading to storage exhaustion and denial of service.

Alon Barad
Alon Barad
7 views•6 min read