Source: node-ajv Version: 8.20.0~ds+~cs6.1.3-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-ajv. CVE-2026-16221[0]: | Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the | 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a | literal backslash character (U+005C) as an authority delimiter. | Node's native WHATWG URL parser, used by fetch, undici, and Node's | http and https clients, normalizes the backslash to a forward slash | for special schemes such as http, https, ws, wss, ftp, and file. As | a result, the two parsers extract different hosts from the same | input string. Applications that use fast-uri to enforce host-based | policy such as allowlists, denylists, loopback or SSRF filtering, | redirect validation, or outbound proxy routing before passing the | same URL into Node's URL or fetch consumers can be steered to an | unintended destination, including cloud metadata endpoints, | loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, | 3.1.4, or 2.4.3. Workarounds: none. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-16221 https://www.cve.org/CVERecord?id=CVE-2026-16221 [1] https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx Please adjust the affected versions in the BTS as needed. Regards, Salvatore

