Openjsf
Openjsf Fast-uri: vulnerabilidades y CVE
Openjsf Fast-uri tiene 13 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses13
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86818 | Media (4.8) | 0.25% | — | 15 sept 2026 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name… |
| CVE-2026-86472 | Media (4.8) | 0.25% | — | 15 sept 2026 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it… |
| CVE-2026-84394 | Alta (7.5) | 0.38% | — | 3 sept 2026 | fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as… |
| CVE-2026-84292 | Alta (7.5) | 0.24% | — | 2 sept 2026 | fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a… |
| CVE-2026-76172 | Alta (7.5) | 0.23% | — | 24 ago 2026 | fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host… |
| CVE-2026-75975 | Alta (7.5) | 0.22% | — | 24 ago 2026 | fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed… |
| CVE-2026-75931 | Alta (7.5) | 0.40% | — | 24 ago 2026 | fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its… |
| CVE-2026-75899 | Alta (7.5) | 0.22% | — | 24 ago 2026 | fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve… |
| CVE-2026-18446 | Alta (7.5) | 0.22% | — | 31 jul 2026 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash… |
| CVE-2026-16221 | Alta (7.5) | 0.25% | — | 19 jul 2026 | Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG… |
| CVE-2026-13676 | Alta (7.5) | 0.48% | — | 29 jun 2026 | fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently… |
| CVE-2026-6322 | Alta (7.5) | 0.68% | — | 5 may 2026 | fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign,… |
| CVE-2026-6321 | Alta (7.5) | 0.77% | — | 4 may 2026 | fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.