fast-uri <=3.1.2/4.0.0 Unicode IDN Canonicalization Bug
CVE-2026-13676 Published on June 29, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.
Vulnerability Analysis
CVE-2026-13676 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Types
Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state. This is generally found in proxies, firewalls, anti-virus software, and other intermediary devices that monitor, allow, deny, or modify traffic based on how the client or server is expected to behave.
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection. For instance, the character strings /./ and / both mean current directory. If /SomeDirectory is a protected directory and an attacker requests /./SomeDirectory, the attacker may be able to gain access to the resource if /./ is not converted to / before the authorization check is performed.
Products Associated with CVE-2026-13676
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
fast-uri:- Version 4.0.0 and below 4.0.1 is affected.
- Version 4.0.1 is unaffected.
- Version 2.3.1 and below 3.1.3 is affected.
- Version 3.1.3 is unaffected.
- Version 0:1.1.2-1.el10_2 and below * is unaffected.
- Version 1786911977 and below * is unaffected.
- Version 1786668856 and below * is unaffected.
- Version 1786908361 and below * is unaffected.
- Version 1784622951 and below * is unaffected.
- Version 1785773509 and below * is unaffected.
- Version 1785413994 and below * is unaffected.
- Version 1785332487 and below * is unaffected.
- Version 1785340831 and below * is unaffected.
- Version 1785332825 and below * is unaffected.
- Version 1785332668 and below * is unaffected.
- Version 1785332694 and below * is unaffected.
- Version 1785411652 and below * is unaffected.
- Version 1784210921 and below * is unaffected.
- Version 1786634825 and below * is unaffected.
- Version 1784194938 and below * is unaffected.
- Version 1784194574 and below * is unaffected.
- Version 1784126822 and below * is unaffected.
- Version 1784127736 and below * is unaffected.
- Version 1783690532 and below * is unaffected.
- Version 1784109883 and below * is unaffected.
- Version 1785530656 and below * is unaffected.
- Version 1784744859 and below * is unaffected.
- Version 1784144829 and below * is unaffected.
- Version 1783596795 and below * is unaffected.
- Version 1783510956 and below * is unaffected.
- Version 1784728481 and below * is unaffected.
- Version 1783559447 and below * is unaffected.
- Version 1784729919 and below * is unaffected.
- Version 1786705347 and below * is unaffected.
- Version 1786706101 and below * is unaffected.
- Version 1786705558 and below * is unaffected.
- Version 1786705646 and below * is unaffected.
- Version 1786706138 and below * is unaffected.
- Version 1786705741 and below * is unaffected.
- Version 1786705777 and below * is unaffected.
- Version 1786705802 and below * is unaffected.
- Version 1786705938 and below * is unaffected.
- Version 1786706577 and below * is unaffected.
- Version 1786706125 and below * is unaffected.
- Version 1786706177 and below * is unaffected.
- Version 1786706188 and below * is unaffected.
- Version 1786706679 and below * is unaffected.
- Version 1786706357 and below * is unaffected.
- Version 1786706612 and below * is unaffected.
- Version 1786706644 and below * is unaffected.
- Version 1786706659 and below * is unaffected.
- Version 1786706880 and below * is unaffected.
- Version 1786701839 and below * is unaffected.
- Version 1786701555 and below * is unaffected.
- Version 1786702052 and below * is unaffected.
- Version 1786702559 and below * is unaffected.
- Version 1786702713 and below * is unaffected.
- Version 1786702264 and below * is unaffected.
- Version 1786702448 and below * is unaffected.
- Version 1786702276 and below * is unaffected.
- Version 1786702440 and below * is unaffected.
- Version 1786702315 and below * is unaffected.
- Version 1786703071 and below * is unaffected.
- Version 1786702563 and below * is unaffected.
- Version 1786702636 and below * is unaffected.
- Version 1786702623 and below * is unaffected.
- Version 1786703137 and below * is unaffected.
- Version 1786702716 and below * is unaffected.
- Version 1786702872 and below * is unaffected.
- Version 1786702949 and below * is unaffected.
- Version 1786702917 and below * is unaffected.
- Version 1786703143 and below * is unaffected.
- Version 1786627460 and below * is unaffected.
- Version 1786626399 and below * is unaffected.
- Version 1786628235 and below * is unaffected.
- Version 1786627106 and below * is unaffected.
- Version 1786629761 and below * is unaffected.
- Version 1786627559 and below * is unaffected.
- Version 1786687918 and below * is unaffected.
- Version 1786629478 and below * is unaffected.
- Version 1786628142 and below * is unaffected.
- Version 1786631508 and below * is unaffected.
- Version 1786628053 and below * is unaffected.
- Version 1786627382 and below * is unaffected.
- Version 1786627430 and below * is unaffected.
- Version 1786629076 and below * is unaffected.
- Version 1786627469 and below * is unaffected.
- Version 1786644072 and below * is unaffected.
- Version 1786688215 and below * is unaffected.
- Version 1786628340 and below * is unaffected.
- Version 1786628623 and below * is unaffected.
- Version 1786632256 and below * is unaffected.
- Version 1786628935 and below * is unaffected.
- Version 1786629548 and below * is unaffected.
- Version 1784737150 and below * is unaffected.
- Version 1783955846 and below * is unaffected.
- Version 1784125838 and below * is unaffected.
- Version 1785776190 and below * is unaffected.
- Version 1785762027 and below * is unaffected.
- Version 1785922764 and below * is unaffected.
- Version 1785956497 and below * is unaffected.
- Version 1785937325 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.