chore(repo): Update dependency fast-uri@<3.1.6 to v3.1.7 [SECURITY] - #10056
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
This PR contains the following updates:
3.1.6→3.1.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
CVE-2026-84394 / GHSA-58mr-gqgx-xq4g
More information
Details
Impact
fast-uriaccepts a host that contains an unbalanced or misplaced authority bracket ([or]) without reporting an error. A host that starts with[but does not end with], such as[@127.0.0.1, is neither validated as an IP literal nor canonicalized as a domain name, soparse()returns it as the host witherrorundefined, while Node'sURL(andhttp.get,axios,got, and other clients built on it) resolve the same string to127.0.0.1. An application that readsparse().hostto make a host decision (an SSRF denylist, a redirect allowlist, or proxy routing) and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried throughnormalize(),equal(), andresolve().Patches
This vulnerability has been patched in fast-uri
4.1.4,3.1.7, and2.4.6.parse()now reportsURI host is malformed.for any host that contains a bracket but is not a valid[IPv6]literal. All users should upgrade.Workarounds
If upgrading is not immediately possible, reject any URL whose host contains a
[or]that is not a well-formed IPv6 literal before making a host decision. Clients that fail closed on credential-bearing URLs, such as Node's globalfetch(), are not affected by the reported vector.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fast-uri vulnerable to authority injection via an unvalidated port in serialize
CVE-2026-84292 / GHSA-qw65-cvwx-89v3
More information
Details
Impact
fast-uriserializes theportcomponent of a URI without validating it. When recomposing the authority,fast-uriescapes the userinfo and host components but concatenates the port verbatim, so aportvalue that is not a sequence of digits can inject authority delimiters. For example, serializing a component whoseportis@127.0.0.1:8124produceshttp://trusted.example:@127.0.0.1:8124/app, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Bothfast-uriand Node'sURLread the result back as the attacker's host with no error, so re-validating the built URI does not catch it.This affects applications that build URIs from parts and assign untrusted data to the
portcomponent (for example a fixed host from configuration and a port taken from user input or a service record). The same path is reachable throughserialize(),normalize(), andequal()in their object forms. Aportobtained fromparse()is always digits and is not affected.Patches
This vulnerability has been patched in fast-uri
4.1.4,3.1.7, and2.4.6.recomposeAuthoritynow rejects any port that is not*DIGITper RFC 3986. All users should upgrade.Workarounds
If upgrading is not immediately possible, validate the
portvalue against the RFC 3986 grammar (digits only) before passing a component toserialize(),normalize(), orequal(), and reject anything else, for exampleif (!/^\d*$/.test(String(port))) throw new Error('invalid port').Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
fastify/fast-uri (fast-uri@<3.1.6)
v3.1.7Compare Source
Configuration
📅 Schedule: (in timezone GMT)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.