[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#CVE-2026-16221

articleHIGH 7.5

CVE-2026-16221: fast-uri Vulnerability Allows URL Parsing Discrepancies and Potential SSRF Attacks

A high-severity vulnerability (CVE-2026-16221, CVSS 7.5) exists in fast-uri versions 2.3.1 through 4.1.0, which can lead to URL parsing discrepancies when used with Node's native WHATWG URL parser. This discrepancy can be exploited to bypass host-based security policies, potentially allowing SSRF attacks or steering to unintended destinations, including cloud metadata endpoints or internal hosts. Affected applications should upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3 immediately.

Jul 20, 20261 source