Description
fast-uri v3.1.0 and earlier decodes percent-encoded path separators (%2F) and dot segments (%2E) before applying dot-segment removal in normalize() and equal(). This makes encoded path data behave like real / and .., so distinct URIs collapse onto the same normalized path.
For example, http://example.com/public/%2e%2e/admin normalizes to http://example.com/admin, and equal() considers them the same URI.
Recommendation
Update the fast-uri package to the latest compatible version. Followings are version details:
Affected version(s): **<= 2.4.0 >= 3.0.0, <= 3.1.0** Patched version(s): **2.4.1 3.1.1**
References
Could your website be exposed too?
SmartScanner can check your website for fast-uri vulnerable to path traversal via percent-encoded dot segments and gives you actionable findings to investigate.
Start a free scanRelated Issues
- fast-uri vulnerable to host confusion via percent-encoded authority delimiters - CVE-2026-6322
- Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules` - CVE-2026-44373
- Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules` - nitro - CVE-2026-44373
- fast-uri vulnerable to host confusion via failed IDN canonicalization - CVE-2026-13676


