Threat Advisory

fast-uri Vulnerabilities Permit Mailto Header Manipulation and URI Validation Evasion

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Two vulnerabilities affect the fast-uri npm package and arise from inconsistent URI parsing and normalization. The first involves percent-encoded mailto field names that can bypass recipient, subject, or body validation during parsing and become active after serialization, potentially enabling attacker-controlled email content or recipients. The second involves improper host case normalization for percent-encoded octets in scheme-relative references, allowing host allowlist or denylist checks to be evaded even though the request ultimately reaches the same DNS/HTTP host. Both vulnerabilities can affect applications that rely on fast-uri output for validation decisions.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Two vulnerabilities affect the fast-uri npm package and arise from inconsistent URI parsing and normalization. The first involves percent-encoded mailto field names that can bypass recipient, subject, or body validation during parsing and become active after serialization, potentially enabling attacker-controlled email content or recipients. The second involves improper host case normalization for percent-encoded octets in scheme-relative references, allowing host allowlist or denylist checks to be evaded even though the request ultimately reaches the same DNS/HTTP host. Both vulnerabilities can affect applications that rely on fast-uri output for validation decisions.[emaillocker id="1283"]

CVE-2026-86818 (CVSS 4.8 — Medium): A vulnerability in fast-uri allows percent-encoded mailto field names such as %74o to bypass validation and introduce attacker-controlled recipients, subjects, or message bodies after serialize(), as the encoded field is not recognized by parse().to but materializes as a literal to= field after serialization, while subject and body can similarly be smuggled through %73ubject and %62ody.

CVE-2026-86472 (CVSS 4.8 — Medium): A vulnerability in fast-uri causes inconsistent host case normalization for percent-encoded octets in scheme-relative references, where %41 decodes to A and causes parse(url).host to return "A.com" while fast-uri.equal returns false, allowing host allowlist or denylist checks to be bypassed even though DNS and HTTP treat the host equivalently.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-jvvf-x445-j334
https://github.com/advisories/GHSA-hrr3-gc8f-f4qj

[/emaillocker]
crossmenu