A high-severity vulnerability affecting fast-uri versions >= 4.0.0, < 4.1.2, rated 7.5 on the CVSS v3 scale, affects various versions of the fast-uri library, including those less than 2.4.4 and between 3.0.0 and 3.1.5. The flaw allows host confusion via a backslash authority introducer, where references that use \, /\, or / as the authority introducer are parsed with no authority, causing the sequence and everything after it to fold into the path. This issue can lead to policy/use desync in applications that enforce host-based policy before passing URLs to Node's URL or fetch consumers, potentially steering them to unintended destinations.
We recommend you to update fast-uri to version 2.4.4, 3.1.5, or 4.1.2.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting fast-uri versions >= 4.0.0, < 4.1.2, rated 7.5 on the CVSS v3 scale, affects various versions of the fast-uri library, including those less than 2.4.4 and between 3.0.0 and 3.1.5. The flaw allows host confusion via a backslash authority introducer, where references that use \, /\, or / as the authority introducer are parsed with no authority, causing the sequence and everything after it to fold into the path. This issue can lead to policy/use desync in applications that enforce host-based policy before passing URLs to Node's URL or fetch consumers, potentially steering them to unintended destinations.
We recommend you to update fast-uri to version 2.4.4, 3.1.5, or 4.1.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]