Interpretation Conflict in fast-uri - CVE-2026-84394

 

Interpretation Conflict in fast-uri - CVE-2026-84394

Published: September 2, 2026


Vulnerability identifier: #VU146817
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84394
CWE-ID: CWE-436
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass host-based security decisions.

The vulnerability exists due to interpretation conflict in URI authority host parsing when processing a URL containing an unclosed or misplaced bracket in the authority. A remote attacker can supply a specially crafted URL to bypass host-based security decisions.

This issue can occur when an application evaluates policy using the parsed host value and then sends the original URL through an HTTP client that resolves the host differently.


Affected software

fast-uri

How to mitigate CVE-2026-84394

Install security update from vendor's website.

fast-uri - addressed in versions 2.4.6, 3.1.7, 4.1.4

External References

Related Security Bulletins