{"api_version":"v1","generated_at":"2026-10-08T14:25:00+00:00","product":{"cve_count":13,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-fast-uri-fast-uri-59dce39b29da","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/fast-uri","name":"fast-uri","next_cursor":null,"observations":[{"affected":"fast-uri: 4.1.3 < 4.1.5","affected_versions_present":true,"cve_id":"CVE-2026-86818","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86818","fixed":"fast-uri: 4.1.5","last_modified":"2026-09-15T12:31:55.631Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-jvvf-x445-j334","primary_source":"","published":"2026-09-15T10:40:38.461Z"},{"affected":"fast-uri: < 2.4.7, 3.0.0 < 3.1.8, 4.0.0 < 4.1.5","affected_versions_present":true,"cve_id":"CVE-2026-86472","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86472","fixed":"fast-uri: 2.4.7, 3.1.8, 4.1.5","last_modified":"2026-09-15T12:35:44.789Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj","primary_source":"","published":"2026-09-15T10:29:50.594Z"},{"affected":"2.4.5 < 2.4.6; 3.1.6 < 3.1.7; 4.1.3 < 4.1.4","affected_versions_present":true,"cve_id":"CVE-2026-84394","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84394","fixed":"2.4.6; 3.1.7; 4.1.4","last_modified":"2026-09-03T13:14:42.123Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g","primary_source":"","published":"2026-09-02T20:25:35.399Z"},{"affected":"fast-uri: < 2.4.6, 3.0.0 < 3.1.7, 4.0.0 < 4.1.4","affected_versions_present":true,"cve_id":"CVE-2026-84292","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84292","fixed":"fast-uri: 2.4.6, 3.1.7, 4.1.4","last_modified":"2026-09-03T13:16:25.237Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3","primary_source":"","published":"2026-09-02T20:09:51.415Z"},{"affected":"2.3.1 < 2.4.5; 3.0.0 < 3.1.6; 4.0.0 < 4.1.3","affected_versions_present":true,"cve_id":"CVE-2026-76172","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76172","fixed":"2.4.5; 3.1.6; 4.1.3","last_modified":"2026-08-24T14:29:37.950Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp","primary_source":"","published":"2026-08-24T10:07:56.440Z"},{"affected":"2.3.1 < 2.4.5; 3.0.0 < 3.1.6; 4.0.0 < 4.1.3","affected_versions_present":true,"cve_id":"CVE-2026-75975","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75975","fixed":"2.4.5; 3.1.6; 4.1.3","last_modified":"2026-08-24T14:30:09.105Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc","primary_source":"","published":"2026-08-24T09:58:07.698Z"},{"affected":"2.4.1 < 2.4.5; 3.1.2 < 3.1.6; 4.0.0 < 4.1.3","affected_versions_present":true,"cve_id":"CVE-2026-75899","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75899","fixed":"2.4.5; 3.1.6; 4.1.3","last_modified":"2026-08-24T16:19:58.701Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf","primary_source":"","published":"2026-08-24T09:40:19.801Z"},{"affected":"2.4.2 < 2.4.5; 3.1.3 < 3.1.6; 4.0.1 < 4.1.3","affected_versions_present":true,"cve_id":"CVE-2026-75931","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75931","fixed":"2.4.5; 3.1.6; 4.1.3","last_modified":"2026-08-24T16:28:48.098Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8","primary_source":"","published":"2026-08-24T09:30:04.212Z"},{"affected":"4.0.0 < 4.1.2; 3.0.0 < 3.1.5; < 2.4.4","affected_versions_present":true,"cve_id":"CVE-2026-18446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-18446","fixed":"4.1.2; 3.1.5; 2.4.4","last_modified":"2026-07-31T17:47:35.325Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7","primary_source":"","published":"2026-07-31T14:37:01.584Z"},{"affected":"2.3.1 < 2.4.3; 3.0.0 < 3.1.4; 4.0.0 < 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-16221","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16221","fixed":"2.4.3; 3.1.4; 4.1.1","last_modified":"2026-07-20T13:53:42.583Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx","primary_source":"","published":"2026-07-19T14:08:32.993Z"},{"affected":"fast-uri: 4.0.0 < 4.0.1, 2.3.1 < 3.1.3","affected_versions_present":true,"cve_id":"CVE-2026-13676","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-13676","fixed":"fast-uri: 4.0.1, 3.1.3","last_modified":"2026-09-11T12:09:12.391Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6","primary_source":"","published":"2026-06-29T13:22:44.674Z"},{"affected":"fast-uri: < 3.1.2","affected_versions_present":true,"cve_id":"CVE-2026-6322","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6322","fixed":"fast-uri: 3.1.2","last_modified":"2026-09-10T12:04:48.155Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc","primary_source":"","published":"2026-05-05T10:29:16.378Z"},{"affected":"fast-uri: < 3.1.1","affected_versions_present":true,"cve_id":"CVE-2026-6321","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6321","fixed":"fast-uri: 3.1.1","last_modified":"2026-09-10T12:04:59.137Z","patch_url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6","primary_source":"","published":"2026-05-04T19:31:57.253Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"fast-uri"}}
