| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-84394 | fixed | vulnerable (no DSA) | vulnerable | fixed | fast-uri accepts a host that contains an unbalanced or misplaced autho ... |
| CVE-2026-84292 | fixed | vulnerable (no DSA) | vulnerable | fixed | fast-uri serializes the port component of a URI without validating it. ... |
| CVE-2026-76172 | fixed | vulnerable (no DSA) | vulnerable | fixed | fast-uri is a URI parser for Node.js. During parsing it runs a legacy ... |
| CVE-2026-75975 | fixed | vulnerable (no DSA) | vulnerable | fixed | fast-uri is a URI parser for Node.js. Its custom parser for bracketed ... |
| CVE-2026-75931 | fixed | vulnerable (no DSA) | vulnerable | fixed | fast-uri is a URI parser for Node.js. It canonicalizes a host to its A ... |
| CVE-2026-75899 | fixed | vulnerable (no DSA) | vulnerable | fixed | fast-uri is a URI parser for Node.js. It decodes percent escapes in a ... |
| CVE-2026-18446 | fixed | vulnerable (no DSA) | fixed | fixed | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forw ... |
| CVE-2026-16221 | fixed | vulnerable (no DSA) | fixed | fixed | Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... |
| CVE-2026-13676 | fixed | vulnerable (no DSA) | fixed | fixed | fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize U ... |
| CVE-2026-6322 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fast-uri normalize() decoded percent-encoded authority delimiters insi ... |
| CVE-2026-6321 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fast-uri decoded percent-encoded path separators and dot segments befo ... |
| CVE-2025-69873 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Reg ... |