Bug 2527747 (CVE-2026-84292) - CVE-2026-84292 fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
Summary: CVE-2026-84292 fast-uri: fast-uri: Authority Injection via Unvalidated Port S...
Keywords:
Status: NEW
Alias: CVE-2026-84292
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2537714 2537715 2537717 2537718 2537719 2537720 2537721 2537722 2537723 2537725 2537726 2537727 2537729 2537730 2537732 2537733 2537734 2537735 2537737 2537738 2537739 2537740 2537741 2537742 2537716 2537724 2537731 2537736
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-02 20:31 UTC by OSIDB Bzimport
Modified: 2026-09-24 11:02 UTC (History)
126 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:71543 0 None None None 2026-09-24 11:02:09 UTC

Description OSIDB Bzimport 2026-09-02 20:31:59 UTC
fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

Comment 1 Jon Orris 2026-09-24 11:02:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:71543 https://access.redhat.com/errata/RHSA-2026:71543


Note You need to log in before you can comment on or make changes to this bug.