CVE-2026-75899
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once.
Leer descripción completaMostrar menos
An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a server-side request forgery and host-policy bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded percent signs. Users should upgrade to a patched version.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1090Proxycommand and control90 % - Impacto secundario
T1565.002Transmitted Data Manipulationimpact70 %
Parser URI con doble decodificación de percent-escapes (CWE-918 SSRF) en entrada remota sin autenticación permite bypasear validaciones de host y redireccionamientos, facilitando SSRF y falsificación de solicitud del servidor.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-174, CWE-918
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-75899",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-75899",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-24T16:16:34.392088Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"affectedData": [
{
"vendor": "fast-uri",
"product": "fast-uri",
"versions": [
{
"status": "affected",
"version": "2.4.1",
"lessThan": "2.4.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.1.2",
"lessThan": "3.1.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "3.1.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.1.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.1.3",
"versionType": "semver"
}
],
"packageURL": "pkg:npm/fast-uri",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-24T10:16:39.960",
"references": [
{
"url": "https://cna.openjsf.org/security-advisories.html",
"tags": [
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"description": [
{
"lang": "en",
"value": "CWE-174"
},
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a server-side request forgery and host-policy bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded percent signs. Users should upgrade to a patched version."
}
],
"lastModified": "2026-09-02T14:43:19.097",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "1EDB4E92-09B0-4B21-9FFE-FE199789F86F",
"versionEndExcluding": "2.4.5",
"versionStartIncluding": "2.4.1"
},
{
"criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "FE262744-646F-4399-8B26-11C21B3954D5",
"versionEndExcluding": "3.1.6",
"versionStartIncluding": "3.1.2"
},
{
"criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "E5821EBB-01F8-44C6-8EFF-BA388AB307D5",
"versionEndExcluding": "4.1.3",
"versionStartIncluding": "4.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}