Skip to content

[audit] high: CVE-2026-13676 in fast-uri@3.1.2 #9

Description

@github-actions

Severity: high
CVE: CVE-2026-13676
Package: fast-uri @ 3.1.2
Vulnerable range: >=3.0.0 <3.1.3
Patched in: >=3.1.3
Dep paths:

  • lib__api-spec>orval>@scalar/openapi-parser>ajv>fast-uri

fast-uri vulnerable to host confusion via failed IDN canonicalization

Reference: GHSA-4c8g-83qw-93j6
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.

Metadata

Metadata

Assignees

No one assigned

    Labels

    audit:cveAutomated pnpm audit finding

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions