#1148183 node-ajv: fast-uri: CVE-2026-86472 CVE-2026-86818

Package:
src:node-ajv
Source:
src:node-ajv
Submitter:
Salvatore Bonaccorso
Date:
2026-09-18 05:35:02 UTC
Severity:
normal
Tags:
#1148183#5
Date:
2026-09-17 20:59:10 UTC
From:
To:
Hi,

The following vulnerabilities were published for node-ajv.

node-ajv/8.20.0~ds+~cs7.1.5-1 provides fast-uri 4.1.4 only afaics, so
needs an update.

CVE-2026-86472[0]:
| fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used
| by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through
| 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to
| lowercase before it percent-decodes the host, so a percent-encoded
| uppercase octet such as %41 decodes to a literal A that is never
| folded. For a scheme-relative reference such as //host there is no
| scheme, so the host canonicalization that would normally repair this
| does not run, and parse, normalize, and equal then disagree on the
| same host. An application that makes a case-sensitive host decision
| on fast-uri output, for example a host allowlist or denylist that
| compares the parsed host or uses equal, can be steered past the
| check with a percent-encoded uppercase octet, and because hostnames
| are case-insensitive in DNS and HTTP the evading spelling still
| reaches the host the check meant to gate. The issue is fixed in
| fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of
| those versions or later. As a workaround, compare hosts case-
| insensitively by lowercasing the parsed host before any allowlist or
| denylist decision.


CVE-2026-86818[1]:
| fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used
| by Fastify and ajv, that added a mailto scheme parser in version
| 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each
| query field name to the reserved names to, subject, and body while
| the name is still percent-encoded, and decodes it only when storing
| it as a generic header, so a percent-encoded spelling of a reserved
| field name is not recognized as that field at parse time but is re-
| emitted as the literal field name when the parsed URI is serialized.
| An application that validates, logs, or displays the recipient list
| from the first parse and then serializes the URI and sends it can
| silently gain an attacker-chosen recipient, and the subject and body
| fields can be smuggled across the same roundtrip. The issue is fixed
| in fast-uri 4.1.5, and users should upgrade to 4.1.5 or later. As a
| workaround, do not act on a mailto URI that fast-uri has re-
| serialized without first decoding and re-validating its recipient,
| subject, and body fields.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86472
https://www.cve.org/CVERecord?id=CVE-2026-86472
[1] https://security-tracker.debian.org/tracker/CVE-2026-86818
https://www.cve.org/CVERecord?id=CVE-2026-86818

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148183#10
Date:
2026-09-18 05:33:55 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-ajv, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148183@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-ajv package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 18 Sep 2026 07:21:59 +0200
Source: node-ajv
Architecture: source
Version: 8.20.0~ds+~cs7.1.6-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1148183
Changes:
 node-ajv (8.20.0~ds+~cs7.1.6-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version (Closes: #1148183, CVE-2026-86472, CVE-2026-86818)
Checksums-Sha1:
 722f5790783f15348f90cb77a245d1c5a1f0865d 2995 node-ajv_8.20.0~ds+~cs7.1.6-1.dsc
 e9eb88d2d29bd89c0979db3889d2ac01bef8cb29 15784 node-ajv_8.20.0~ds+~cs7.1.6.orig-ajv-formats.tar.xz
 3939c24effa97ec54be84dd83beee5d658132ae4 50444 node-ajv_8.20.0~ds+~cs7.1.6.orig-fast-uri.tar.xz
 252fb7dcb0ee564c8ccca05ce47f18a5869e455e 157948 node-ajv_8.20.0~ds+~cs7.1.6.orig.tar.xz
 f8a78677a88c992e6ed74c1d52f4d1b93097ce6f 84228 node-ajv_8.20.0~ds+~cs7.1.6-1.debian.tar.xz
Checksums-Sha256:
 1511e285554c419b4e91bcc1049d05bf286122d94c0f742d7b83e202da641a77 2995 node-ajv_8.20.0~ds+~cs7.1.6-1.dsc
 cb2d4c8318b09e8dc95400cef30007678adde921f2f96e40555186cf0b284795 15784 node-ajv_8.20.0~ds+~cs7.1.6.orig-ajv-formats.tar.xz
 2aa9299a0dd9c14ec9c63e5b6854d67547e3f8d067438723351ee9ed8700d7ff 50444 node-ajv_8.20.0~ds+~cs7.1.6.orig-fast-uri.tar.xz
 dc39049f1740e184d79b4ba4d59b804f7c2dee3885e6eda9fbcfdfeb73799d8f 157948 node-ajv_8.20.0~ds+~cs7.1.6.orig.tar.xz
 14e2436cfb926f2760040c005f6e7764f50e24710ebdefd93d3fc48310b755c4 84228 node-ajv_8.20.0~ds+~cs7.1.6-1.debian.tar.xz
Files:
 c09630c446fe556991d16d1ddebe51eb 2995 javascript optional node-ajv_8.20.0~ds+~cs7.1.6-1.dsc
 d731ebdc55c16ebfc43bac566641a2bb 15784 javascript optional node-ajv_8.20.0~ds+~cs7.1.6.orig-ajv-formats.tar.xz
 1cbb0b164e919fee114639c6331fe0b9 50444 javascript optional node-ajv_8.20.0~ds+~cs7.1.6.orig-fast-uri.tar.xz
 a4bf97e93b7b8a0e274d0267430f0c7b 157948 javascript optional node-ajv_8.20.0~ds+~cs7.1.6.orig.tar.xz
 6a408fae64dab0fbb7c297135ae3bc23 84228 javascript optional node-ajv_8.20.0~ds+~cs7.1.6-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqsywYACgkQ9tdMp8mZ
7unrSw/+NYdo2CX3W44kdJTf0x8gn65wVF7C00QY0Fz/g25NwJwr8pYjC5s2MIc+
Q2Ex19W7zzXod/GgNbFxwubgTxKnWaTf/5PBAw62oJogjiSHyT41EiDJkJU8ZoxK
FwmhWBdSLT18BXhwvwDnjcjRln9vQb1SpcYnJVQdQDlDTzgRu9DbatnWHqa0/ne+
aKNSFLzGthot6BxZAXJqmEApzQ/vTOoQuuaEhc9zwB2N9tBGUCCBzNbQAItJrtsk
xaOHArXgKG4gwZ24lp4m0PYLFTNbosVGabGMWEOa4o1ymTj4r4J7G1wCZhRzNwua
Op9lvifeha9biIBQ81ASdtWcH0+K4Yx4NeIc84OGJRj8MqjFGW+Tl4YlfM9I4JmK
ndE16bUl7kBO5YO+6VdM8mIp1OoI8gzdO9l5WfDodUoB8EaPXVFes52vdY5MEpfz
b3J0JgrDNQ1sJl2KH0WKqQ8flQz2BKcc6QkvQeOI+3CTovf6GSVlvE7h0RA6mDId
ZsSx+kT/c2BxXB/J9dh5bpN2soDA7kGHYMGw4yhvhKBh07tp87aPjjzTHHWwIJyz
/yBQHw+rtoSFDHyThiqs/SGemQeIBafgnKLfLp3vhbxD9mLkVlE5estiQ+OXfjM5
f8D1Be96+aZ5eqeavhrvpeGx1hbVyu/MEHX21ua5JI7upIeVUpg=
=Os/k
-----END PGP SIGNATURE-----