CVE-2026-75975
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses.
Leer descripción completaMostrar menos
No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1090Proxycommand and control90 %
Parser de URI con validación insuficiente (CWE-20) permite bypass de políticas de direcciones mediante redirección a destinos IPv6 locales/privados; aplicación en Node.js normaliza URLs malformadas sin error, facilitando SSRF y escaneo de servicios internos (AV:N, PR:N, UI:N).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-20, CWE-918
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-75975",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-75975",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-24T14:29:55.795156Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"affectedData": [
{
"vendor": "fast-uri",
"product": "fast-uri",
"versions": [
{
"status": "affected",
"version": "2.3.1",
"lessThan": "2.4.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.0.0",
"lessThan": "3.1.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "3.1.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.1.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.1.3",
"versionType": "semver"
}
],
"packageURL": "pkg:npm/fast-uri",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-24T10:16:40.237",
"references": [
{
"url": "https://cna.openjsf.org/security-advisories.html",
"tags": [
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version."
}
],
"lastModified": "2026-09-02T14:44:17.457",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "3B52B356-9E41-4817-B8A5-C5A5ED7FEDC0",
"versionEndExcluding": "2.4.5",
"versionStartIncluding": "2.3.1"
},
{
"criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "1AC6ED82-63FA-4FF2-BB90-48BBBB9A0653",
"versionEndExcluding": "3.1.6",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "E5821EBB-01F8-44C6-8EFF-BA388AB307D5",
"versionEndExcluding": "4.1.3",
"versionStartIncluding": "4.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}