Description
fast-uri v3.1.1 and earlier decodes percent-encoded authority delimiters (%40 as @, %3A as :) inside the host component and serializes them back as raw characters. This changes the URI structure, turning a hostname into userinfo plus a different host.
For example, http://trusted.com%40evil.com/ normalizes to http://[email protected]/, which reparses as host `evil.
Recommendation
Update the fast-uri package to the latest compatible version. Followings are version details:
Affected version(s): **<= 2.4.0 >= 3.0.0, <= 3.1.1** Patched version(s): **2.4.1 3.1.2**
References
Could your website be exposed too?
SmartScanner can check your website for fast-uri vulnerable to host confusion via percent-encoded authority delimiters and gives you actionable findings to investigate.
Start a free scanRelated Issues
- fast-uri vulnerable to host confusion via literal backslash authority delimiter - CVE-2026-16221
- fast-uri vulnerable to host confusion via backslash authority introducer - CVE-2026-18446
- fast-uri vulnerable to host confusion via failed IDN canonicalization - CVE-2026-13676
- fast-uri vulnerable to path traversal via percent-encoded dot segments - CVE-2026-6321


