fast-uri
fast-uri
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at fast-uri, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-86818 | 15 Sep 2026 | fast-uri: 4.1.3 < 4.1.5 | fast-uri: 4.1.5 | Update reference ↗ |
| CVE-2026-86472 | 15 Sep 2026 | fast-uri: < 2.4.7, 3.0.0 < 3.1.8, 4.0.0 < 4.1.5 | fast-uri: 2.4.7, 3.1.8, 4.1.5 | Update reference ↗ |
| CVE-2026-84394 | 2 Sep 2026 | 2.4.5 < 2.4.6; 3.1.6 < 3.1.7; 4.1.3 < 4.1.4 | 2.4.6; 3.1.7; 4.1.4 | Update reference ↗ |
| CVE-2026-84292 | 2 Sep 2026 | fast-uri: < 2.4.6, 3.0.0 < 3.1.7, 4.0.0 < 4.1.4 | fast-uri: 2.4.6, 3.1.7, 4.1.4 | Update reference ↗ |
| CVE-2026-76172 | 24 Aug 2026 | 2.3.1 < 2.4.5; 3.0.0 < 3.1.6; 4.0.0 < 4.1.3 | 2.4.5; 3.1.6; 4.1.3 | Update reference ↗ |
| CVE-2026-75975 | 24 Aug 2026 | 2.3.1 < 2.4.5; 3.0.0 < 3.1.6; 4.0.0 < 4.1.3 | 2.4.5; 3.1.6; 4.1.3 | Update reference ↗ |
| CVE-2026-75899 | 24 Aug 2026 | 2.4.1 < 2.4.5; 3.1.2 < 3.1.6; 4.0.0 < 4.1.3 | 2.4.5; 3.1.6; 4.1.3 | Update reference ↗ |
| CVE-2026-75931 | 24 Aug 2026 | 2.4.2 < 2.4.5; 3.1.3 < 3.1.6; 4.0.1 < 4.1.3 | 2.4.5; 3.1.6; 4.1.3 | Update reference ↗ |
| CVE-2026-18446 | 31 Jul 2026 | 4.0.0 < 4.1.2; 3.0.0 < 3.1.5; < 2.4.4 | 4.1.2; 3.1.5; 2.4.4 | Update reference ↗ |
| CVE-2026-16221 | 19 Jul 2026 | 2.3.1 < 2.4.3; 3.0.0 < 3.1.4; 4.0.0 < 4.1.1 | 2.4.3; 3.1.4; 4.1.1 | Update reference ↗ |
| CVE-2026-13676 | 29 Jun 2026 | fast-uri: 4.0.0 < 4.0.1, 2.3.1 < 3.1.3 | fast-uri: 4.0.1, 3.1.3 | Update reference ↗ |
| CVE-2026-6322 | 5 May 2026 | fast-uri: < 3.1.2 | fast-uri: 3.1.2 | Update reference ↗ |
| CVE-2026-6321 | 4 May 2026 | fast-uri: < 3.1.1 | fast-uri: 3.1.1 | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.