fix(deps): update dependency fast-uri@>=3.0.0 <3.1.3 to ^4.1.5 [security] - #1164
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thank you for following the naming conventions! 🙏 |
…ity] Signed-off-by: Renovate Bot <bot@renovateapp.com>
f8fdd69 to
3236ca2
Compare
|
Superseded by the consolidated dependency update now on |
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This PR contains the following updates:
^4.1.2→^4.1.5](https://renovatebot.com/diffs/npm/fast-uri@>=3.0.0 <3.1.3/4.1.2/4.1.5)fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
CVE-2026-86818 / GHSA-jvvf-x445-j334
More information
Details
Impact
fast-uri'smailtoscheme parser compares each query field name to the reserved names (to,subject,body) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as%74o(percent-encodedto) is not recognized as a recipient at parse time (parse().toshows only the legitimate recipient) but materializes as a literalto=field afterserialize(), and reparsing then treats it as a recipient. The same technique smugglessubjectandbodythrough%73ubjectand%62ody.An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on
parse().to, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extrato=sees nothing, because the injected field appears only afterfast-uriserializes.Patches
Upgrade to
fast-uri4.1.5.Workarounds
Percent-decode and compare mailto field names case-insensitively before trusting
parse().to, or re-check the recipient list on the serialized output rather than only on the initial parse, until upgrading.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
CVE-2026-86472 / GHSA-hrr3-gc8f-f4qj
More information
Details
Impact
fast-urifolds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as%41decodes to a literalAthat is never folded. For a scheme-relative reference (//host) there is no scheme, so the host canonicalization that repairs this on a scheme-bearing URL does not run. As a resultparse,normalize, andequaldisagree on the same host:parse("//%41.com").hostreturns"A.com"whileparse("//a.com").hostandparse("//A.com").hostreturn"a.com", andequal("//%41.com", "//a.com")isfalseeven thoughequal("//A.com", "//a.com")istrue. An application that makes a case-sensitive host decision onfast-urioutput for a scheme-relative reference, for example a host allowlist or denylist that comparesparse(url).hostor usesfast-uri.equal, can be steered past the check with a percent-encoded uppercase octet. Because a hostname is case-insensitive in DNS and HTTP routing, the evading spelling reaches the same host the check meant to gate, so the effect is check evasion rather than reaching a different registrable host.Patches
Upgrade to
fast-uri4.1.5, 3.1.8, or 2.4.7.Workarounds
Compare hosts case-insensitively (lowercase the parsed host before any allowlist or denylist decision), or avoid making case-sensitive host decisions on scheme-relative input until upgrading.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
fastify/fast-uri (fast-uri@>=3.0.0 <3.1.3)
v4.1.5Compare Source
This security release fixes the following medium-severity security advisories:
mailtoheader injection via percent-encoded field-name desynchronizationUsers of the v4 release line should upgrade to v4.1.5.
Full Changelog: fastify/fast-uri@v4.1.4...v4.1.5
v4.1.4Compare Source
This is a security release that fixes the following high-severity security advisories:
serialize()Users of the v4 release line should upgrade to v4.1.4.
Full Changelog: fastify/fast-uri@v4.1.3...v4.1.4
v4.1.3Compare Source
This release addresses the following high-severity security advisories:
Users of the v4 release line should upgrade to v4.1.3.
Full Changelog: fastify/fast-uri@v4.1.2...v4.1.3
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.