highCVSS 7.5Vulnerability

CVE-2026-76172

### Impact `fast-uri` decodes percent-encoded characters in the scheme component with the legacy global `unescape()` and serializes the result back as raw characters, without re-escaping it or validating it as a scheme. A scheme that decodes to characters outside the RFC 3986 scheme grammar can therefore introduce structure the original input did not contain. For example, `%2f%2fevil.example:/pwn` parses with no authority (`parse().host` is `undefined`), but `resolve()` and `normalize()` return `//evil.example:/pwn`, which reparses with host `evil.example`. The `%uXXXX` form (`%u002f%u002fevil.example:/pwn`) produces the same result, and a scheme containing `%0d%0a` reaches the output as a raw CR LF. Applications that normalize or resolve untrusted URLs before a redirect check, host allowlist, or outbound request decision, especially ones that treat a missing authority as same-origin, can be steered to an attacker-chosen authority, and a normalized URI placed in a response header can carry an injected CR LF. ### Patches Upgrade to `fast-uri` >= 4.1.3, or >= 3.1.6 in the v3.x release line, or >= 2.4.5 in the v2.x release line. ### Workarounds None. Upgrade to the patched version.

Properties

ghsa_id
GHSA-jqff-g426-hqxp
severity
high
summary
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
cvss_score
7.5
cve_id
CVE-2026-76172
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
false
ghsa_published
2026-09-02T15:41:53Z
source_url
https://github.com/advisories/GHSA-jqff-g426-hqxp
ghsa_updated
2026-09-02T15:41:56Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/fast-uri

AFFECTS (1)

[Software]npm/fast-uri

HAS_WEAKNESS (1)

[Weakness]Improper Handling of URL Encoding (Hex Encoding)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76172 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal