Inappropriate Encoding for Output Context Affecting fast-uri package, versions >=4.1.3 <4.1.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-FASTURI-19846653
  • published16 Sept 2026
  • disclosed15 Sept 2026
  • creditJace, manus-pi

Introduced: 15 Sep 2026

NewCVE-2026-86818  (opens in a new tab)
CWE-838  (opens in a new tab)

How to fix?

Upgrade fast-uri to version 4.1.5 or higher.

Overview

fast-uri is a Dependency-free RFC 3986 URI toolbox

Affected versions of this package are vulnerable to Inappropriate Encoding for Output Context in the mailto parser when handling percent-encoded query field names. An attacker can manipulate email recipients, subjects, or body content by crafting specially formatted mailto URIs that exploit the desynchronization between parsing and serialization. This may result in emails being sent to unintended recipients or with altered content.

CVSS Base Scores

version 4.0
version 3.1