- **fast-uri** (high, transitive) - fix: yes - [fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references](https://github.com/advisories/GHSA-5jgf-p345-68v8) - [fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization](https://github.com/advisories/GHSA-f65p-4m7j-42xc) - [fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding](https://github.com/advisories/GHSA-fph4-wmhf-6fwf) - [fast-uri vulnerable to host confusion via percent-encoded scheme normalization](https://github.com/advisories/GHSA-jqff-g426-hqxp) --- Found by [Security Audit](https://github.com/mstuart/vitals/actions/runs/34122190004). Updated automatically; closes itself when `npm audit --audit-level=high` is clean. If a fix needs a transitive pin Dependabot cannot express, add an `overrides` entry to `package.json`.
Found by Security Audit. Updated automatically; closes itself when
npm audit --audit-level=highis clean.If a fix needs a transitive pin Dependabot cannot express, add an
overridesentry topackage.json.