Echo: fast-uri: security update to 2.4.5

high Tenable Self-Hosted Container Security Plugin ID 461662

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the
complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed
attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed
literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP
client then connects to a local service over loopback, and other malformed literals collapse to private-
range addresses. No error is set on the parsed result, so an application checking the error field cannot
detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects,
proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a
server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but
not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The
issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar
and mark malformed literals as authority errors. Users should upgrade to a patched version.
(CVE-2026-75975)

Solution

Update the fast-uri library and its related packages to version 2.4.5 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-75975

Plugin Details

Severity: High

ID: 461662

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-75975

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 8/24/2026

Reference Information

CVE: CVE-2026-75975