CVE-2026-86818
### Impact `fast-uri`'s `mailto` scheme parser compares each query field name to the reserved names (`to`, `subject`, `body`) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as `%74o` (percent-encoded `to`) is not recognized as a recipient at parse time (`parse().to` shows only the legitimate recipient) but materializes as a literal `to=` field after `serialize()`, and reparsing then treats it as a recipient. The same technique smuggles `subject` and `body` through `%73ubject` and `%62ody`. An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on `parse().to`, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extra `to=` sees nothing, because the injected field appears only after `fast-uri` serializes. ### Patches Upgrade to `fast-uri` 4.1.5. ### Workarounds Percent-decode and compare mailto field names case-insensitively before trusting `parse().to`, or re-check the recipient list on the serialized output rather than only on the initial parse, until upgrading.
Properties
- severity
- medium
- summary
- fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
- cvss_score
- 4.8
- retrieved_at
- 2026-09-30T02:27:15+00:00
- ghsa_published
- 2026-09-29T23:51:16Z
- source_url
- https://github.com/advisories/GHSA-jvvf-x445-j334
- ghsa_updated
- 2026-09-29T23:51:17Z
- ghsa_id
- GHSA-jvvf-x445-j334
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-86818
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- signal_observed_at
- 2026-09-30T02:27:15+00:00
- is_ghsa_only
- false
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph