fast-uri@2.4.6

Dependency-free RFC 3986 URI toolbox

  • latest version

    4.2.1

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    18 days ago

  • licenses detected

    • >=0.0.1 <3.0.3
  • Direct Vulnerabilities

    Known vulnerabilities in the fast-uri package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Handling of Case Sensitivity

    fast-uri is a Dependency-free RFC 3986 URI toolbox

    Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity due to inconsistent normalization in the host component. An attacker can gain unauthorized access to restricted resources or services by submitting a specially crafted URI containing percent-encoded uppercase characters, which may bypass host allowlists or denylists in applications relying on case-sensitive host validation.

    How to fix Improper Handling of Case Sensitivity?

    Upgrade fast-uri to version 2.4.7, 3.1.8, 4.1.5 or higher.

    <2.4.7>=3.0.0 <3.1.8>=4.0.0 <4.1.5