{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": [
              "cpe:2.3:a:openjsf:fast-uri:2.4.5:*:*:*:*:node.js:*:*",
              "cpe:2.3:a:openjsf:fast-uri:3.1.6:*:*:*:*:node.js:*:*",
              "cpe:2.3:a:openjsf:fast-uri:4.1.3:*:*:*:*:node.js:*:*"
            ],
            "extracted_events": [
              {
                "introduced": "2.4.5"
              },
              {
                "last_affected": "2.4.5"
              },
              {
                "introduced": "3.1.6"
              },
              {
                "last_affected": "3.1.6"
              },
              {
                "introduced": "4.1.3"
              },
              {
                "last_affected": "4.1.3"
              }
            ],
            "source": "CPE_STRING"
          },
          "events": [
            {
              "introduced": "21e274eb54bc738748f66746f4ec1c1e4f919413"
            },
            {
              "last_affected": "4e99790cadffc4b4fdaef9912cb503b328505be0"
            }
          ],
          "repo": "https://github.com/fastify/fast-uri",
          "type": "GIT"
        }
      ],
      "versions": [
        "2.4.5",
        "3.1.6",
        "4.1.3"
      ]
    }
  ],
  "aliases": [
    "GHSA-58mr-gqgx-xq4g"
  ],
  "database_specific": {
    "cna_assigner": "openjs",
    "cwe_ids": [
      "CWE-436"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84394.json",
    "unresolved_ranges": [
      {
        "extracted_events": [
          {
            "introduced": "2.4.5"
          },
          {
            "fixed": "2.4.6"
          },
          {
            "introduced": "3.1.6"
          },
          {
            "fixed": "3.1.7"
          },
          {
            "introduced": "4.1.3"
          },
          {
            "fixed": "4.1.4"
          }
        ],
        "source": "AFFECTED_FIELD"
      }
    ]
  },
  "details": "fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse() returns it as the host with error undefined, while Node's URL and the HTTP clients built on it resolve the same string to a different host. An application that reads the parsed host to make a host decision, such as an SSRF denylist, a redirect allowlist, or proxy routing, and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried through normalize, equal, and resolve. This affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4, where parse() reports a malformed host for any host that contains a bracket but is not a valid IPv6 literal.",
  "id": "CVE-2026-84394",
  "modified": "2026-09-06T03:30:33.247931095Z",
  "published": "2026-09-02T20:25:35.399Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://cna.openjsf.org/security-advisories.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84394.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84394"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority"
}