Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0 ๐Ÿ“– 2 min read

CVE-2026-86818: CVE-2026-86818: Mailto Header Injection via Percent-Encoded Field-Name Desynchronization in fast-uri

CVE-2026-86818: Mailto Header Injection via Percent-Encoded Field-Name Desynchronization in fast-uri Vulnerability ID: CVE-2026-86818 CVSS Score: 4.8 Published: 2026-09-29 A security-critical desynchronization vulne

CVE-2026-86818: Mailto Header Injection via Percent-Encoded Field-Name Desynchronization in fast-uri

Vulnerability ID: CVE-2026-86818
CVSS Score: 4.8
Published: 2026-09-29

A security-critical desynchronization vulnerability exists in fast-uri versions 4.1.3 and 4.1.4. Due to incorrect order-of-operations, the mailto scheme parser validates raw percent-encoded parameter keys instead of normalized keys, but subsequently decodes and writes them into a generic headers object. When the parsed URI is serialized, these keys are re-emitted literally, allowing attackers to bypass validation boundaries and smuggle unauthorized recipients, subjects, or body parameters in downstream mailing applications.

TL;DR

A validation discrepancy in fast-uri allows remote attackers to smuggle mailto parameters such as 'to', 'subject', and 'body' by using percent-encoded names like '%74o', bypassing safety validations before serialization.

โš ๏ธ Exploit Status: POC

Technical Details

  • CWE ID: CWE-172 / CWE-436
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 4.8
  • Exploitability Subscore: 2.2
  • Impact Subscore: 2.5
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • fast-uri versions 4.1.3 and 4.1.4
  • Node.js applications parsing mailto schemas with fast-uri
  • Downstream packages containing transient dependencies on fast-uri v4.1.3/v4.1.4, including Fastify and ajv
  • fast-uri: >= 4.1.3, <= 4.1.4 (Fixed in: 4.1.5)

Code Analysis

Commit: f40a88f

Ensure mailto parameter names are decoded and lower-cased prior to parsing, and implement header canonicalization in serialization

Commit: 5dabb86

Implement structural normalization updates for mailto parameter logic

Commit: a071da6

Tag and release version 4.1.5 containing the vulnerability fix

Exploit Details

  • GitHub Advisory: Details on reproducing the parser desynchronization using percent-encoded parameters

Mitigation Strategies

  • Upgrade fast-uri dependency to version 4.1.5 or newer
  • Enforce dependency overrides or resolutions in package.json to update transitive fast-uri instances in Fastify and ajv
  • Implement a pre-serialization filter that manually purges reserved keys from parsed.headers

Remediation Steps:

  1. Scan the project node_modules using 'npm ls fast-uri' to identify vulnerable versions
  2. Add overrides for fast-uri version 4.1.5 inside the project package.json file
  3. Re-generate the lockfile using 'npm install' or 'yarn install' to apply the resolution
  4. Verify that validation logic parses and serializes mailto links correctly using the updated package

References

Read the full report for CVE-2026-86818 on our website for more details including interactive diagrams and full exploit analysis.

๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.