Echo: fast-uri: security update to 2.4.5

high Tenable Cloud Security Plugin ID 455278

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then
decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or
resolve can turn nested percent-encoded input into a different network destination such as a loopback
hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that
live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode
the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI
before outbound routing, redirect validation, or a host-policy check can receive a destination different
from the one the original encoded host represented, giving a server-side request forgery and host-policy
bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up
to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3.
The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded
percent signs. Users should upgrade to a patched version. (CVE-2026-75899)

Solution

Update the fast-uri library and its related packages to version 2.4.5 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-75899

Plugin Details

Severity: High

ID: 455278

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-75899

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 8/24/2026

Reference Information

CVE: CVE-2026-75899