CVE-2026-13676

high

Description

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.

References

https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6

https://cna.openjsf.org/security-advisories.html

https://access.redhat.com/errata/RHSA-2026:63371

https://access.redhat.com/errata/RHSA-2026:61314

https://access.redhat.com/errata/RHSA-2026:60520

https://access.redhat.com/errata/RHSA-2026:60386

https://access.redhat.com/errata/RHSA-2026:59593

https://access.redhat.com/errata/RHSA-2026:57590

https://access.redhat.com/errata/RHSA-2026:57194

https://access.redhat.com/errata/RHSA-2026:57191

https://access.redhat.com/errata/RHSA-2026:57013

https://access.redhat.com/errata/RHSA-2026:56431

https://access.redhat.com/errata/RHSA-2026:56366

https://access.redhat.com/errata/RHSA-2026:54760

https://access.redhat.com/errata/RHSA-2026:51349

https://access.redhat.com/errata/RHSA-2026:51348

https://access.redhat.com/errata/RHSA-2026:51342

https://access.redhat.com/errata/RHSA-2026:51197

https://access.redhat.com/errata/RHSA-2026:51196

https://access.redhat.com/errata/RHSA-2026:50758

https://access.redhat.com/errata/RHSA-2026:50479

https://access.redhat.com/errata/RHSA-2026:50340

https://access.redhat.com/errata/RHSA-2026:49642

https://access.redhat.com/errata/RHSA-2026:48126

https://access.redhat.com/errata/RHSA-2026:48124

https://access.redhat.com/errata/RHSA-2026:47728

https://access.redhat.com/errata/RHSA-2026:44268

https://access.redhat.com/errata/RHSA-2026:44239

https://access.redhat.com/errata/RHSA-2026:43038

https://access.redhat.com/errata/RHSA-2026:42815

https://access.redhat.com/errata/RHSA-2026:41929

https://access.redhat.com/errata/RHSA-2026:41928

https://access.redhat.com/errata/RHSA-2026:41066

https://access.redhat.com/errata/RHSA-2026:40945

https://access.redhat.com/errata/RHSA-2026:40765

https://access.redhat.com/errata/RHSA-2026:40262

https://access.redhat.com/errata/RHSA-2026:40118

https://access.redhat.com/errata/RHSA-2026:37628

https://access.redhat.com/errata/RHSA-2026:37585

https://access.redhat.com/errata/RHSA-2026:37186

Details

Source: Mitre, NVD

Published: 2026-06-29

Updated: 2026-09-07

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High

EPSS

EPSS: 0.00278