Skip to content

fix(deps): update dependency fast-uri@>=3.0.0 <3.1.3 to ^4.1.5 [security] - #1164

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-fast-uri-=3.0.0-3.1.3-vulnerability
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-fast-uri-=3.0.0-3.1.3-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
fast-uri@>=3.0.0 <3.1.3 [^4.1.2 → ^4.1.5](https://renovatebot.com/diffs/npm/fast-uri@>=3.0.0 <3.1.3/4.1.2/4.1.5) age confidence

fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization

CVE-2026-86818 / GHSA-jvvf-x445-j334

More information

Details

Impact

fast-uri's mailto scheme parser compares each query field name to the reserved names (to, subject, body) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as %74o (percent-encoded to) is not recognized as a recipient at parse time (parse().to shows only the legitimate recipient) but materializes as a literal to= field after serialize(), and reparsing then treats it as a recipient. The same technique smuggles subject and body through %73ubject and %62ody.

An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on parse().to, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extra to= sees nothing, because the injected field appears only after fast-uri serializes.

Patches

Upgrade to fast-uri 4.1.5.

Workarounds

Percent-decode and compare mailto field names case-insensitively before trusting parse().to, or re-check the recipient list on the serialized output rather than only on the initial parse, until upgrading.

Severity

  • CVSS Score: 4.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets

CVE-2026-86472 / GHSA-hrr3-gc8f-f4qj

More information

Details

Impact

fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference (//host) there is no scheme, so the host canonicalization that repairs this on a scheme-bearing URL does not run. As a result parse, normalize, and equal disagree on the same host: parse("//%41.com").host returns "A.com" while parse("//a.com").host and parse("//A.com").host return "a.com", and equal("//%41.com", "//a.com") is false even though equal("//A.com", "//a.com") is true. An application that makes a case-sensitive host decision on fast-uri output for a scheme-relative reference, for example a host allowlist or denylist that compares parse(url).host or uses fast-uri.equal, can be steered past the check with a percent-encoded uppercase octet. Because a hostname is case-insensitive in DNS and HTTP routing, the evading spelling reaches the same host the check meant to gate, so the effect is check evasion rather than reaching a different registrable host.

Patches

Upgrade to fast-uri 4.1.5, 3.1.8, or 2.4.7.

Workarounds

Compare hosts case-insensitively (lowercase the parsed host before any allowlist or denylist decision), or avoid making case-sensitive host decisions on scheme-relative input until upgrading.

Severity

  • CVSS Score: 4.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).

⚠️ Renovate does not enforce Minimum Release Age for bump, lockfileUpdate, or rollback updates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).


Release Notes

fastify/fast-uri (fast-uri@>=3.0.0 <3.1.3)

v4.1.5

Compare Source

⚠️ Security Warning

This security release fixes the following medium-severity security advisories:

Users of the v4 release line should upgrade to v4.1.5.

Full Changelog: fastify/fast-uri@v4.1.4...v4.1.5

v4.1.4

Compare Source

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v4 release line should upgrade to v4.1.4.

Full Changelog: fastify/fast-uri@v4.1.3...v4.1.4

v4.1.3

Compare Source

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v4 release line should upgrade to v4.1.3.

Full Changelog: fastify/fast-uri@v4.1.2...v4.1.3


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 32fb1d54-ca18-4432-b745-00cd75284f1e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

…ity]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate
renovate Bot force-pushed the renovate/npm-fast-uri-=3.0.0-3.1.3-vulnerability branch from f8fdd69 to 3236ca2 Compare October 2, 2026 18:08
@prisis

prisis commented Oct 3, 2026

Copy link
Copy Markdown
Member

Superseded by the consolidated dependency update now on main.

@prisis prisis closed this Oct 3, 2026
@prisis
prisis deleted the renovate/npm-fast-uri-=3.0.0-3.1.3-vulnerability branch October 3, 2026 10:59
@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (^4.1.5). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant