#1143071 node-ajv: CVE-2026-13676

Package:
src:node-ajv
Source:
src:node-ajv
Submitter:
Salvatore Bonaccorso
Date:
2026-07-30 13:07:04 UTC
Severity:
normal
Tags:
#1143071#5
Date:
2026-07-30 05:29:38 UTC
From:
To:
Hi,

The following vulnerability was published for node-ajv.

CVE-2026-13676[0]:
| fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize
| Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion
| path calls a helper that does not exist on the global URL
| constructor, silently leaving the host in its original Unicode form
| while normalize() and equal() still return values that differ from a
| WHATWG-compatible URL parser. Applications that use fast-uri to
| enforce host-based policy (denylists, loopback filtering, redirect
| validation, outbound proxy routing) before passing the same URL to
| Node's URL or fetch can be bypassed when the two implementations
| resolve the same input to different hosts. Patches: upgrade to fast-
| uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds:
| enforce host policy using the same URL parser used for the actual
| request, or reject non-ASCII hosts before policy checks.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-13676
https://www.cve.org/CVERecord?id=CVE-2026-13676
[1] https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143071#8
Date:
2026-07-30 12:43:49 UTC
From:
To:
Hello,

Bug #1143071 in node-ajv reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-ajv/-/commit/1a8ee68c4ade12072e4406f8167a552a6bfbe32d

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143071

#1143071#13
Date:
2026-07-30 12:43:48 UTC
From:
To:
Hello,

Bug #1143071 in node-ajv reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-ajv/-/commit/1a8ee68c4ade12072e4406f8167a552a6bfbe32d

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143071

#1143071#18
Date:
2026-07-30 13:05:53 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-ajv, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143071@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-ajv package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 30 Jul 2026 14:50:10 +0200
Source: node-ajv
Architecture: source
Version: 8.20.0~ds+~cs7.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1143064 1143071
Changes:
 node-ajv (8.20.0~ds+~cs7.1.2-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version
     (Closes: #1143064, #1143071, CVE-2026-16221, CVE-2026-13676)
Checksums-Sha1:
 676c5e8171c9aad024f61aa8cc7e009ff93d2f8c 2995 node-ajv_8.20.0~ds+~cs7.1.2-1.dsc
 e9eb88d2d29bd89c0979db3889d2ac01bef8cb29 15784 node-ajv_8.20.0~ds+~cs7.1.2.orig-ajv-formats.tar.xz
 bb3f3e3efe349b9047ddb0f1d14ef010b67ec15a 28820 node-ajv_8.20.0~ds+~cs7.1.2.orig-fast-uri.tar.xz
 252fb7dcb0ee564c8ccca05ce47f18a5869e455e 157948 node-ajv_8.20.0~ds+~cs7.1.2.orig.tar.xz
 691ff06439db89affd1799b2e95779e097ba5393 82644 node-ajv_8.20.0~ds+~cs7.1.2-1.debian.tar.xz
Checksums-Sha256:
 a6162316ff36f6ee7d893079ca55e596b4c7a5d997b719ba15ffdea202f9515a 2995 node-ajv_8.20.0~ds+~cs7.1.2-1.dsc
 cb2d4c8318b09e8dc95400cef30007678adde921f2f96e40555186cf0b284795 15784 node-ajv_8.20.0~ds+~cs7.1.2.orig-ajv-formats.tar.xz
 933b221c2c241cdebf7d8820704ba759f53e4a3183ba24ddc3ab919b6f961b15 28820 node-ajv_8.20.0~ds+~cs7.1.2.orig-fast-uri.tar.xz
 dc39049f1740e184d79b4ba4d59b804f7c2dee3885e6eda9fbcfdfeb73799d8f 157948 node-ajv_8.20.0~ds+~cs7.1.2.orig.tar.xz
 909d3ddfe8e57085f5c20a53db709af35aba0ae97f77122af9c77c6d8290b188 82644 node-ajv_8.20.0~ds+~cs7.1.2-1.debian.tar.xz
Files:
 c7b89665d7ccdce4ba1d064558448720 2995 javascript optional node-ajv_8.20.0~ds+~cs7.1.2-1.dsc
 d731ebdc55c16ebfc43bac566641a2bb 15784 javascript optional node-ajv_8.20.0~ds+~cs7.1.2.orig-ajv-formats.tar.xz
 00d7c5f444be961cd3e8d12da393763a 28820 javascript optional node-ajv_8.20.0~ds+~cs7.1.2.orig-fast-uri.tar.xz
 a4bf97e93b7b8a0e274d0267430f0c7b 157948 javascript optional node-ajv_8.20.0~ds+~cs7.1.2.orig.tar.xz
 faa35211da5aae77a870ce3daf5f93e5 82644 javascript optional node-ajv_8.20.0~ds+~cs7.1.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmprSREACgkQ9tdMp8mZ
7ungww//bpcwXx9HIhLpzql/E8WBpL60jl4b8BHOl3EGjh8YmrYqf+lYiDAfnxsM
zQSRIOPa+pBJoZ4ggwzyTfLQ7LBo5mdJA0KzfoP2WbvzJaGuZeqIeVlHUAl7BWXw
CLJT1qm0i/rfXUJVJEznyWXESe2pghDD5WtMnsRvJXvQw0D/LncSQ7tuES1FQqug
dIENbTAlUifHgQd4x106lPIA60F4i8hcmFR+8GosEwJdJ3gxjQePn5IE+ZFJFiWV
zAdjYLqdtW2f9zi04F++uxGjAtWAF3wvs58I6WRxuImU6uH/xwV+LIUK9Htf7OFG
njDEBwwJQLr/PSeV2a3j53UVy+UBbSgPWq6CRuMPdLpulOLAc0mozvdpYn0R2IRg
n4oir5yBJ1mW6Gqwx0mPQRxqOAZ4cptCJBhPcUzsOColR/tne8FmfYAhldZvgxpQ
O5YUmylQU/rIiTAOv1uwG2LWXJp5qk38AkNoGGKfUPQqQ61cyRFoJo9hnlBwSDrQ
o2x+LRo9Um05kEC9W4gqvKqC/2c4dXwER9g5oaOnHqSZmDpZYRqq/53i7HmVpiqc
0Kao3HlWDZBxWjFuACVmzew/SQUaDcjfyjYvjBo3DX7Wo5ychLds0RvIuG26raSG
PX3mvgoANOjWh+xjA5UF0xWm1YZ+20QFyo7xvvpolfQBg1+32xk=
=89kc
-----END PGP SIGNATURE-----