CVE-2026-13676

HIGH CVSS 3.1: 7.5 EPSS 0.38%
Updated Sep 11, 2026
Fast-Uri
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions 2.3.1 — 4.0.1
Fixed In 3.1.3
Type CWE-436, CWE-551
Vendor Fast-Uri
Public PoC No

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts.

Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Openjsf Fast-Uri
cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*
2.3.1 3.1.3
Openjsf Fast-Uri
cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*
4.0.0 4.0.1

References 45

https://cna.openjsf.org/security-advisories.html
ce714d77-add3-4f53-aff5-83d477b104bb
https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
ce714d77-add3-4f53-aff5-83d477b104bb
https://access.redhat.com/errata/RHSA-2026:37186
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:37585
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:37628
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:40118
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:40262
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:40765
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:40945
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:41066
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:41928
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:41929
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:42815
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:43038
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/security/cve/CVE-2026-13676
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://bugzilla.redhat.com/show_bug.cgi?id=2494197
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:44239
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:44268
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:48124
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:48126
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:49642
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50340
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50479
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:47728
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:51196
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:51197
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:51342
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:51348
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:51349
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:50758
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:54760
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:56366
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:56431
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:57013
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:57191
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:57194
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:57590
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:59593
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60386
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:60520
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:61314
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:63371
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:66488
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:66545
0b0ca135-0b70-47e7-9f44-1890c2a1c46c