SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-75931

HIGH · CVSS 7.5 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-08

CyberRota Analysis

AI-Generated

The fast-uri library for Node.js is vulnerable due to inconsistent host canonicalization, which can lead to host confusion and policy bypass when applications extract and resolve hosts. This discrepancy allows an attacker to manipulate input such that an application may make decisions based on one host while the actual destination is different. Organizations using affected versions (2.4.2 to 2.4.5, 3.1.3 to 3.1.6, and 4.0.1 to 4.1.3) should prioritize upgrading to the patched versions to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75931
Severity
HIGH
CVSS
7.5
EPSS
0.23%

Original NVD Description

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.

Related CVEs

Other vulnerabilities affecting the same vendor(s)