Echo: fast-uri: security update to 2.4.5

high Tenable Self-Hosted Container Security Plugin ID 463280

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme
component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike
the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes
parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or
normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-
parses to that host. An application that allowlists on the parsed host, or treats a reference with no
authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site
redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-
standard escape forms, widening the issue past upstream filters, and control characters in the scheme can
reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not
including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue
is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should
upgrade to a patched version. (CVE-2026-76172)

Solution

Update the fast-uri library and its related packages to version 2.4.5 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-76172

Plugin Details

Severity: High

ID: 463280

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-76172

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 8/24/2026

Reference Information

CVE: CVE-2026-76172