SCA: security update for fast-uri (GHSA-v2hh-gcrm-f6hx)

high Tenable Cloud Security Plugin ID 445032

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up
to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native
WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a
forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two
parsers extract different hosts from the same input string. Applications that use fast-uri to enforce
host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or
outbound proxy routing before passing the same URL into Node's URL or fetch consumers can be steered to an
unintended destination, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade
to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none. (CVE-2026-16221)

Solution

Update the fast-uri library and its related packages to version 2.4.3 or later.

See Also

https://github.com/advisories/GHSA-v2hh-gcrm-f6hx

Plugin Details

Severity: High

ID: 445032

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 7/22/2026

Updated: 7/22/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-16221

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/21/2026

Vulnerability Publication Date: 7/19/2026

Reference Information

CVE: CVE-2026-16221

cwe: CWE-436