Source: node-ajv Version: 8.20.0~ds+~cs7.1.2-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-ajv. CVE-2026-18446[0]: | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double | forward slash to recognize a URI authority, so a reference that uses | a backslash based introducer in place of it (backslash backslash, | forward slash backslash, or backslash forward slash) is parsed with | no authority and folds into the path. Node's native WHATWG URL | parser instead treats a backslash as interchangeable with a forward | slash for special schemes, so the two parsers extract different | hosts from the same input. Applications that use fast-uri to enforce | host based policy such as allowlists, SSRF filtering, or redirect | validation before passing the same URL into Node's URL or fetch | consumers can be steered to an unintended host. Upgrade to fast-uri | 4.1.2, 3.1.5, or 2.4.4. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-18446 https://www.cve.org/CVERecord?id=CVE-2026-18446 [1] https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7 Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
