Interpretation Conflict in fast-uri - CVE-2026-75931
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass host-based policy checks.
The vulnerability exists due to interpretation conflict in the resolve() host canonicalization logic when resolving scheme-relative references against a scheme-bearing base. A remote attacker can supply a specially crafted scheme-relative reference to bypass host-based policy checks.
Re-parsing the resolved URI can yield a different host than the one returned by resolve().