Overview
About vulnerability
Impact
fast-uri decodes percent-encoded characters in the scheme component with the legacy global unescape() and serializes the result back as raw characters, without re-escaping it or validating it as a scheme. A scheme that decodes to characters outside the RFC 3986 scheme grammar can therefore introduce structure the original input did not contain.
For example, %2f%2fevil.example:/pwn parses with no authority (parse().host is undefined), but resolve() and normalize() return //evil.example:/pwn, which reparses with host evil.example. The %uXXXX form (%u002f%u002fevil.example:/pwn) produces the same result, and a scheme containing %0d%0a reaches the output as a raw CR LF.
Applications that normalize or resolve untrusted URLs before a redirect check, host allowlist, or outbound request decision, especially ones that treat a missing authority as same-origin, can be steered to an attacker-chosen authority, and a normalized URI placed in a response header can carry an injected CR LF.
Patches
Upgrade to fast-uri >= 4.1.3, or >= 3.1.6 in the v3.x release line, or >= 2.4.5 in the v2.x release line.
Workarounds
None. Upgrade to the patched version.
Details
- Affected product:
- AngularJS , Fastify , Node.js , React , Vue , ajv , ajv-compiler , ajv-draft-04 , ajv-errors , ajv-formats , ajv-keywords , api-extractor-model , babel-loader , cache-loader , css-loader , css-minimizer-webpack-plugin , devkit , esbuild-loader , extract-css-chunks-webpack-plugin , fast-json-stringify , fast-json-stringify-compiler , fast-uri , file-loader , fork-ts-checker-webpack-plugin , friendly-errors-webpack-plugin , hard-source-webpack-plugin , html-webpack-plugin , light-my-request , mini-css-extract-plugin , minimizer-webpack-plugin , nuxt , optimize-css-assets-webpack-plugin , postcss-loader , rushstack , schema-utils , style-resources-loader , table , thread-loader , time-fix-plugin , ts-command-line , tsdoc , url-loader , webpack , webpack-dev-middleware , webpack-dev-server , webpackbar , worker-loader
- Affected packages:
- fastify @ 4.29.1 (+463 more)