mediumCVSS 4.8Vulnerability

CVE-2026-86472

### Impact `fast-uri` folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as `%41` decodes to a literal `A` that is never folded. For a scheme-relative reference (`//host`) there is no scheme, so the host canonicalization that repairs this on a scheme-bearing URL does not run. As a result `parse`, `normalize`, and `equal` disagree on the same host: `parse("//%41.com").host` returns `"A.com"` while `parse("//a.com").host` and `parse("//A.com").host` return `"a.com"`, and `equal("//%41.com", "//a.com")` is `false` even though `equal("//A.com", "//a.com")` is `true`. An application that makes a case-sensitive host decision on `fast-uri` output for a scheme-relative reference, for example a host allowlist or denylist that compares `parse(url).host` or uses `fast-uri.equal`, can be steered past the check with a percent-encoded uppercase octet. Because a hostname is case-insensitive in DNS and HTTP routing, the evading spelling reaches the same host the check meant to gate, so the effect is check evasion rather than reaching a different registrable host. ### Patches Upgrade to `fast-uri` 4.1.5, 3.1.8, or 2.4.7. ### Workarounds Compare hosts case-insensitively (lowercase the parsed host before any allowlist or denylist decision), or avoid making case-sensitive host decisions on scheme-relative input until upgrading.

Properties

severity
medium
summary
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
cvss_score
4.8
retrieved_at
2026-09-30T02:27:15+00:00
ghsa_published
2026-09-29T23:54:25Z
source_url
https://github.com/advisories/GHSA-hrr3-gc8f-f4qj
ghsa_updated
2026-09-29T23:54:26Z
ghsa_id
GHSA-hrr3-gc8f-f4qj
last_source
GitHub Advisory Database
cve_id
CVE-2026-86472
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
signal_observed_at
2026-09-30T02:27:15+00:00
is_ghsa_only
false

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/fast-uri

AFFECTS (1)

→[Software]npm/fast-uri

HAS_WEAKNESS (1)

→[Weakness]Improper Handling of Case Sensitivity

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86472 (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal