CVE-2026-13676

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.
References
Link Resource
https://cna.openjsf.org/security-advisories.html Vendor Advisory
https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6 Patch Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:37186
https://access.redhat.com/errata/RHSA-2026:37585
https://access.redhat.com/errata/RHSA-2026:37628
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40262
https://access.redhat.com/errata/RHSA-2026:40765
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:41929
https://access.redhat.com/errata/RHSA-2026:42815
https://access.redhat.com/errata/RHSA-2026:43038
https://access.redhat.com/errata/RHSA-2026:44239
https://access.redhat.com/errata/RHSA-2026:44268
https://access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:48124
https://access.redhat.com/errata/RHSA-2026:48126
https://access.redhat.com/errata/RHSA-2026:49642
https://access.redhat.com/errata/RHSA-2026:50340
https://access.redhat.com/errata/RHSA-2026:50479
https://access.redhat.com/errata/RHSA-2026:50758
https://access.redhat.com/errata/RHSA-2026:51196
https://access.redhat.com/errata/RHSA-2026:51197
https://access.redhat.com/errata/RHSA-2026:51342
https://access.redhat.com/errata/RHSA-2026:51348
https://access.redhat.com/errata/RHSA-2026:51349
https://access.redhat.com/errata/RHSA-2026:54760
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:57191
https://access.redhat.com/errata/RHSA-2026:57194
https://access.redhat.com/errata/RHSA-2026:57590
https://access.redhat.com/errata/RHSA-2026:59593
https://access.redhat.com/errata/RHSA-2026:60386
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:61314
https://access.redhat.com/errata/RHSA-2026:63371
https://access.redhat.com/errata/RHSA-2026:66488
https://access.redhat.com/errata/RHSA-2026:66545
https://access.redhat.com/security/cve/CVE-2026-13676 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2494197 Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-06-29 14:16

Updated : 2026-09-11 13:17


NVD link : CVE-2026-13676

Mitre link : CVE-2026-13676

CVE.ORG link : CVE-2026-13676


JSON object : View

Products Affected

openjsf

  • fast-uri
CWE
CWE-436

Interpretation Conflict

CWE-551

Incorrect Behavior Order: Authorization Before Parsing and Canonicalization