fast-uri is vulnerable to Server-Side Request Forgery (SSRF)
75
High Risk
fast-uri's serialize() writes an object's port value into the URI authority without checking that it only contains digits. A port value containing @ or another authority delimiter lets the rebuilt URI string address a different userinfo and host than the caller intended. An application that serializes a URI from user controlled port data can have that URI silently redirected to an attacker-chosen host. The fix rejects any non-numeric port value before serialization.
You are affected if you are using a version that falls within the vulnerable range and you call serialize() with a port value that can contain untrusted data.
fast-uri is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 2.4.5, 3.0.0 - 3.1.6 and 4.0.0 - 4.1.3.
Upgrade the fast-uri library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.