CVE-2026-84394

Public on 2026-09-03
Modified on 2026-09-04
Description
A flaw was found in fast-uri. The library incorrectly processes Uniform Resource Identifier (URI) hosts containing unbalanced brackets, leading to a discrepancy in how the host is parsed by fast-uri compared to other HTTP clients. This host confusion can allow an attacker to bypass security policies, such as Server-Side Request Forgery (SSRF) denylists or redirect allowlists, by causing an application to evaluate its policy against an incorrect host string. This could result in unintended network requests or access to unauthorized resources.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 dotnet10.0 Not Affected
Amazon Linux 2027 Preview dotnet10.0 Not Affected
Amazon Linux 2023 dotnet6.0 No Fix Planned
Amazon Linux 2023 dotnet8.0 Not Affected
Amazon Linux 2023 dotnet9.0 Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N