Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-13676

PUBLISHED 28.08.2026

CNA: openjs

fast-uri vulnerable to host confusion via failed IDN canonicalization

Обновлено: 29.06.2026
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.

CWE

Идентификатор Описание
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

CVSS

Оценка Severity Версия Базовый вектор
7.5 HIGH 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.38% LOW 31.41 30.08.2026

Доп. Информация

Product Status

fast-uri
Product: fast-uri
Vendor: fast-uri
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 4.0.0 до 4.0.1 affected
Наблюдалось в версии 4.0.1 unaffected
Наблюдалось в версиях от 2.3.1 до 3.1.3 affected
Наблюдалось в версии 3.1.3 unaffected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 29.06.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none yes partial 2.0.3 29.06.2026

fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization

Обновлено: 28.08.2026

CVSS

Оценка Severity Версия Базовый вектор
7.5 HIGH 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Ссылки

https://access.redhat.com/security/cve/CVE-2026-13676
https://bugzilla.redhat.com/show_bug.cgi?id=2494197
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json
https://access.redhat.com/errata/RHSA-2026:57590
https://access.redhat.com/errata/RHSA-2026:57191
https://access.redhat.com/errata/RHSA-2026:60386
https://access.redhat.com/errata/RHSA-2026:42815
https://access.redhat.com/errata/RHSA-2026:50479
https://access.redhat.com/errata/RHSA-2026:50340
https://access.redhat.com/errata/RHSA-2026:48126
https://access.redhat.com/errata/RHSA-2026:49642
https://access.redhat.com/errata/RHSA-2026:41929
https://access.redhat.com/errata/RHSA-2026:54760
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:43038
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:50758
https://access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:40765
https://access.redhat.com/errata/RHSA-2026:37628
https://access.redhat.com/errata/RHSA-2026:44268
https://access.redhat.com/errata/RHSA-2026:37186
https://access.redhat.com/errata/RHSA-2026:44239
https://access.redhat.com/errata/RHSA-2026:37585
https://access.redhat.com/errata/RHSA-2026:48124
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:40262
https://access.redhat.com/errata/RHSA-2026:51342
https://access.redhat.com/errata/RHSA-2026:51349
https://access.redhat.com/errata/RHSA-2026:51348
https://access.redhat.com/errata/RHSA-2026:51196
https://access.redhat.com/errata/RHSA-2026:51197
https://access.redhat.com/errata/RHSA-2026:57194
https://access.redhat.com/errata/RHSA-2026:59593

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.