fast-uri is vulnerable to Server-Side Request Forgery (SSRF)
75
High Risk
The library does not fully validate RFC 3986 grammar for bracketed IPv6 literals in the host component. A malformed literal with invalid trailing text is silently truncated to a different valid IPv6 address and no error is reported. Host-policy checks can therefore be bypassed and requests routed to loopback or link-local addresses while validation appears to pass. The fix validates IPv6 literals and fails closed on malformed input during normalization.
You are affected if you are using a version that falls within the vulnerable range and your application normalizes or resolves untrusted or externally influenced URIs before performing host-policy checks.
fast-uri is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.3.1 - 2.4.4, 3.0.0 - 3.1.5 and 4.0.0 - 4.1.2.
Upgrade the fast-uri library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant