CVE-2026-16221

NameCVE-2026-16221
DescriptionImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node's URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1143064

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-ajv (PTS)bullseye6.12.6-2fixed
bookworm6.12.6-3fixed
trixie8.12.0~ds+~2.1.1-5vulnerable
forky, sid8.20.0~ds+~cs7.1.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-ajvsourcebullseye(not affected)
node-ajvsourcebookworm(not affected)
node-ajvsource(unstable)8.20.0~ds+~cs7.1.2-11143064

Notes

[trixie] - node-ajv <no-dsa> (Minor issue)
[bookworm] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
[bullseye] - node-ajv <not-affected> (Uses uri-js, not the vulnerable fast-uri; fast-uri adopted only in ajv 8.x)
https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx
Embedded fast-uri used and provided as node-fast-uri, starting with forky

Search for package or bug name: Reporting problems