AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-86472.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Impact `fast-uri` folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as `%41` decodes to a literal `A` that is never folded. For a scheme-relative reference (`//host`) there is no scheme, so the host canonicalization that repairs this on a scheme-bearing URL does not run. As a result `parse`, `normalize`, and `equal` disagree on the same host: `parse("//%41.com").host` returns `"A.com"` while `parse("//a.com").host` and `parse("//A.com").host` return `"a.com"`, and `equal("//%41.com", "//a.com")` is `false` even though `equal("//A.com", "//a.com")` is `true`. An application that makes a case-sensitive host decision on `fast-uri` output for a scheme-relative reference, for example a host allowlist or denylist that compares `parse(url).host` or uses `fast-uri.equal`, can be steered past the check with a percent-encoded uppercase octet. Because a hostname is case-insensitive in DNS and HTTP routing, the evading spelling reaches the same host the check meant to gate, so the effect is check evasion rather than reaching a different registrable host. ### Patches Upgrade to `fast-uri` 4.1.5, 3.1.8, or 2.4.7. ### Workarou

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-hrr3-gc8f-f4qj

Open original source · Updated Sep 29, 2026

fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmfast-uri< 2.4.72.4.7
npmfast-uri>= 3.0.0, < 3.1.83.1.8
npmfast-uri>= 4.0.0, < 4.1.54.1.5

Original records & references

PUBLISHED 2026-09-29T19:54:25-04:00
MODIFIED 2026-09-29T19:54:26-04:00
INGESTED 2026-10-06T11:43:09-04:00