PT-2026-36996 · Npm+1 · Fast-Uri+1

·

CVE-2026-6322

·

Published

2026-05-05

·

Updated

2026-07-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions fast-uri versions prior to 3.1.2
Description The normalize() function decoded percent-encoded authority delimiters within the host component and re-emitted them as raw delimiters during serialization. This allows a host combining an allowed domain, an encoded at-sign, and a different domain to be re-emitted with the at-sign as a raw userinfo separator, effectively changing the URI's authority to the second domain. Applications that normalize untrusted URLs before performing host allowlist checks, redirect validation, or outbound request routing can be steered to an authority different from the one specified in the input.
Recommendations Update to version 3.1.2 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BE61221
CLEANSTART-2026-LC05413
CVE-2026-6322
GHSA-V39H-62P7-JPJC
RHSA-2026:34160
RHSA-2026:42078

Affected Products

Confluence
Fast-Uri