highCVSS 7.5Vulnerability

CVE-2026-75975

### Impact `fast-uri` does not validate the complete RFC 3986 grammar for bracketed IPv6 literals, so a malformed literal with invalid trailing text is silently truncated to a different valid IPv6 address with no error reported. For example, `normalize('http://[::not-valid]/private')` returns `http://[::]/private`, and `[fc00::not-hex]` and `[fe80::not-hex]` collapse to `[fc00::]` and `[fe80::]`. An application that normalizes an untrusted URL before an outbound request, redirect, or host-policy check can be routed to a local or private address such as loopback (`::1`), unique-local, or link-local. Because `parse().error` is unset for these inputs, checking it does not protect the consumer. ### Patches Upgrade to `fast-uri` 2.4.5, 3.1.6, or 4.1.3. Malformed IPv6 literals are now rejected with a host error instead of being normalized to a valid address. ### Workarounds Reject untrusted URLs whose host is a bracketed IPv6 literal before passing them to `fast-uri`, or route outbound requests against an explicit allowlist of addresses rather than trusting the normalized host.

Properties

ghsa_id
GHSA-f65p-4m7j-42xc
severity
high
summary
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
cvss_score
7.5
cve_id
CVE-2026-75975
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
false
ghsa_published
2026-09-02T15:43:30Z
source_url
https://github.com/advisories/GHSA-f65p-4m7j-42xc
ghsa_updated
2026-09-02T15:43:32Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/fast-uri

AFFECTS (1)

[Software]npm/fast-uri

HAS_WEAKNESS (2)

[Weakness]Improper Input Validation
[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75975 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal