Severity: high
CVE: CVE-2026-16221
Package: fast-uri @ 3.1.2
Vulnerable range: >=3.0.0 <=3.1.3
Patched in: >=3.1.4
Dep paths:
lib__api-spec>orval>@scalar/openapi-parser>ajv>fast-uri
fast-uri vulnerable to host confusion via literal backslash authority delimiter
Reference: GHSA-v2hh-gcrm-f6hx
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: high
CVE: CVE-2026-16221
Package:
fast-uri@3.1.2Vulnerable range:
>=3.0.0 <=3.1.3Patched in:
>=3.1.4Dep paths:
lib__api-spec>orval>@scalar/openapi-parser>ajv>fast-uriReference: GHSA-v2hh-gcrm-f6hx
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.