mediumCVSS 4.8Vulnerability

CVE-2026-86818

### Impact `fast-uri`'s `mailto` scheme parser compares each query field name to the reserved names (`to`, `subject`, `body`) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as `%74o` (percent-encoded `to`) is not recognized as a recipient at parse time (`parse().to` shows only the legitimate recipient) but materializes as a literal `to=` field after `serialize()`, and reparsing then treats it as a recipient. The same technique smuggles `subject` and `body` through `%73ubject` and `%62ody`. An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on `parse().to`, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extra `to=` sees nothing, because the injected field appears only after `fast-uri` serializes. ### Patches Upgrade to `fast-uri` 4.1.5. ### Workarounds Percent-decode and compare mailto field names case-insensitively before trusting `parse().to`, or re-check the recipient list on the serialized output rather than only on the initial parse, until upgrading.

Properties

severity
medium
summary
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
cvss_score
4.8
retrieved_at
2026-09-30T02:27:15+00:00
ghsa_published
2026-09-29T23:51:16Z
source_url
https://github.com/advisories/GHSA-jvvf-x445-j334
ghsa_updated
2026-09-29T23:51:17Z
ghsa_id
GHSA-jvvf-x445-j334
last_source
GitHub Advisory Database
cve_id
CVE-2026-86818
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
signal_observed_at
2026-09-30T02:27:15+00:00
is_ghsa_only
false

Related Entities (5)

VULNERABLE_TO (1)

←[Software]npm/fast-uri

AFFECTS (1)

→[Software]npm/fast-uri

HAS_WEAKNESS (2)

→[Weakness]Interpretation Conflict
→[Weakness]Encoding Error

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86818 (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal