fast-uri vulnerable to host confusion via failed IDN canonicalization
Package
Affected versions
>= 4.0.0, < 4.0.1
>= 3.0.0, < 3.1.3
>= 2.3.1, < 2.4.2
Patched versions
4.0.1
3.1.3
2.4.2
Description
Published by the National Vulnerability Database
Jun 29, 2026
Published to the GitHub Advisory Database
Jul 21, 2026
Reviewed
Jul 21, 2026
Last updated
Sep 11, 2026
Impact
fast-uriversions>= 2.3.1, <= 4.0.0fail to canonicalize Unicode/IDN hostnames for HTTP-family URLs. The IDN conversion path callsURL.domainToASCII(...)on the global WHATWGURLconstructor, where that helper does not exist. The resultingTypeErroris silently routed intoparsed.error, butparse(),normalize(), andequal()all return with the host left in its original Unicode form.For example,
http://127。0。0。1/is treated byfast-urias host127。0。0。1, while Node's WHATWG URL parser andfetch()canonicalize the same input to127.0.0.1.Applications that use
fast-urito enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL into Node's URL orfetch()consumers see a policy/use desync and can be steered to an unintended destination.Patches
Upgrade to
fast-uriv4.0.1, v3.1.3, or v2.4.2Workarounds
None. Upgrade to the patched version.
References