fast-uri

Dependency-free RFC 3986 URI toolbox

npm latest 4.1.3 BSD-3-Clause

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

4.1.3

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

5 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

5

fast-uri vulnerable to host confusion via failed IDN canonicalization

Affected range

SEMVER: introduced 4.0.0; fixed 4.0.1SEMVER: introduced 3.0.0; fixed 3.1.3SEMVER: introduced 2.3.1; fixed 2.4.2

Fixed versions: 4.0.1, 3.1.3, 2.4.2

fast-uri vulnerable to host confusion via percent-encoded authority delimiters

Affected range

SEMVER: introduced 3.0.0; fixed 3.1.2SEMVER: introduced 0; fixed 2.4.1

Fixed versions: 3.1.2, 2.4.1

fast-uri vulnerable to path traversal via percent-encoded dot segments

Affected range

SEMVER: introduced 3.0.0; fixed 3.1.1SEMVER: introduced 0; fixed 2.4.1

Fixed versions: 3.1.1, 2.4.1

fast-uri vulnerable to host confusion via backslash authority introducer

Affected range

SEMVER: introduced 0; fixed 2.4.4SEMVER: introduced 3.0.0; fixed 3.1.5SEMVER: introduced 4.0.0; fixed 4.1.2

Fixed versions: 2.4.4, 3.1.5, 4.1.2

fast-uri vulnerable to host confusion via literal backslash authority delimiter

Affected range

SEMVER: introduced 2.3.1; fixed 2.4.3SEMVER: introduced 3.0.0; fixed 3.1.4SEMVER: introduced 4.0.0; fixed 4.1.1

Fixed versions: 2.4.3, 3.1.4, 4.1.1