Every CVE whose affected-product data names Openjsf Fast-uri, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (11)
CVE-2026-13676 — CVSS 7.5 (high): fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path…
CVE-2026-16221 — CVSS 7.5 (high): Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal…
CVE-2026-18446 — CVSS 7.5 (high): fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a…
CVE-2026-6321 — CVSS 7.5 (high): fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal()…
CVE-2026-6322 — CVSS 7.5 (high): fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters…
CVE-2026-75899 — CVSS 7.5 (high): fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second…
CVE-2026-75931 — CVSS 7.5 (high): fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a…
CVE-2026-75975 — CVSS 7.5 (high): fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid…
CVE-2026-76172 — CVSS 7.5 (high): fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the…
CVE-2026-84292 — CVSS 7.5 (high): fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are…
CVE-2026-84394 — CVSS 7.5 (high): fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an…