AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-86818.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Impact `fast-uri`'s `mailto` scheme parser compares each query field name to the reserved names (`to`, `subject`, `body`) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as `%74o` (percent-encoded `to`) is not recognized as a recipient at parse time (`parse().to` shows only the legitimate recipient) but materializes as a literal `to=` field after `serialize()`, and reparsing then treats it as a recipient. The same technique smuggles `subject` and `body` through `%73ubject` and `%62ody`. An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on `parse().to`, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extra `to=` sees nothing, because the injected field appears only after `fast-uri` serializes. ### Patches Upgrade to `fast-uri` 4.1.5. ### Workarounds Percent-decode and compare mailto field names cas

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-jvvf-x445-j334

Open original source · Updated Sep 29, 2026

fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmfast-uri>= 4.1.3, < 4.1.54.1.5

Original records & references

PUBLISHED 2026-09-29T19:51:16-04:00
MODIFIED 2026-09-29T19:51:17-04:00
INGESTED 2026-10-06T11:43:09-04:00