« Volver al listado

CVE-2026-84292

Estado: AnalizadaAlta (7.5)—

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it.

Leer descripción completaMostrar menos

This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-84292",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-84292",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-03T13:16:05.344208Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "affectedData": [
        {
          "vendor": "fast-uri",
          "product": "fast-uri",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.4.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "2.4.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.0.0",
              "lessThan": "3.1.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "3.1.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.1.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.1.4",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/fast-uri",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-02T20:17:39.543",
  "references": [
    {
      "url": "https://cna.openjsf.org/security-advisories.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    },
    {
      "url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "description": [
        {
          "lang": "en",
          "value": "CWE-116"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986."
    },
    {
      "lang": "es",
      "value": "fast-uri serializa el componente de puerto de una URI sin validarlo. Al recomponer la autoridad, los componentes userinfo y host se escapan, pero el puerto se concatena textualmente, por lo que un valor de puerto que no es una secuencia de dígitos puede inyectar delimitadores de autoridad, degradando el host previsto a userinfo y apuntando la autoridad a un host controlado por el atacante. Tanto fast-uri como la URL de Node leen el resultado como el host del atacante sin error, por lo que revalidar la URI construida no lo detecta. Esto afecta a las aplicaciones que construyen URIs a partir de partes y asignan datos no confiables al componente de puerto a través de las funciones serialize, normalize o equal en sus formas de objeto. El problema afecta a las versiones de fast-uri anteriores a la 2.4.6, desde la 3.0.0 anteriores a la 3.1.7, y desde la 4.0.0 anteriores a la 4.1.4. Se ha corregido en la 2.4.6, la 3.1.7 y la 4.1.4, donde recomposeAuthority rechaza cualquier puerto que no sea una secuencia de dígitos según la RFC 3986."
    }
  ],
  "lastModified": "2026-09-28T23:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA090E1A-63E4-4E27-A6E2-46832F88ACAE",
              "versionEndExcluding": "2.4.6"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AEABE9A-FF2D-467B-BE01-A7319D079CF5",
              "versionEndExcluding": "3.1.7",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9219F9B3-72F1-4647-927D-571EAA2BC6C6",
              "versionEndExcluding": "4.1.4",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}