HIGHnpm →
fast-uri vulnerable to host confusion via failed IDN canonicalization
fast-uri vulnerable to host confusion via failed IDN canonicalization
Affected packages
- fast-uri
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.38%
- EPSS percentile
- 31.2%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 31%.
Sources
- https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
- https://nvd.nist.gov/vuln/detail/CVE-2026-13676
- https://github.com/fastify/fast-uri/pull/188
- https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05
- https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bd
- https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1d
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json
- https://github.com/fastify/fast-uri/releases/tag/v4.0.1
- https://github.com/fastify/fast-uri/releases/tag/v3.1.3
- https://github.com/fastify/fast-uri/releases/tag/v2.4.2
- https://github.com/fastify/fast-uri
- https://cna.openjsf.org/security-advisories.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2494197
- https://access.redhat.com/security/cve/CVE-2026-13676
- https://access.redhat.com/errata/RHSA-2026:49642
- https://access.redhat.com/errata/RHSA-2026:48126
- https://access.redhat.com/errata/RHSA-2026:48124
- https://access.redhat.com/errata/RHSA-2026:44268
- https://access.redhat.com/errata/RHSA-2026:44239
- https://access.redhat.com/errata/RHSA-2026:43038
- https://access.redhat.com/errata/RHSA-2026:42815
- https://access.redhat.com/errata/RHSA-2026:41929
- https://access.redhat.com/errata/RHSA-2026:41928
- https://access.redhat.com/errata/RHSA-2026:41066
- https://access.redhat.com/errata/RHSA-2026:40945
- https://access.redhat.com/errata/RHSA-2026:40765
- https://access.redhat.com/errata/RHSA-2026:40262
- https://access.redhat.com/errata/RHSA-2026:40118
- https://access.redhat.com/errata/RHSA-2026:37628
- https://access.redhat.com/errata/RHSA-2026:37585
- https://access.redhat.com/errata/RHSA-2026:37186
Structured record: https://osv.dev/vulnerability/GHSA-4c8g-83qw-93j6
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta