Bug 2537724 - CVE-2026-84292 openbao: fast-uri: Authority Injection via Unvalidated Port Serialization [epel-all]
Summary: CVE-2026-84292 openbao: fast-uri: Authority Injection via Unvalidated Port Se...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: openbao
Version: epel10
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Dave Dykstra
QA Contact:
URL:
Whiteboard: {"flaws": ["3c35cd5c-1bf1-43c0-a646-1...
Depends On:
Blocks: CVE-2026-84292
TreeView+ depends on / blocked
 
Reported: 2026-09-22 05:52 UTC by Ganesh
Modified: 2026-09-22 22:36 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-22 22:36:28 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-09-22 05:52:19 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

Comment 1 Dave Dykstra 2026-09-22 22:36:28 UTC
OpenBao has no server side javascript so this vulnerability is not applicable.


Note You need to log in before you can comment on or make changes to this bug.