← Vulnerability feed

Vulnerability record · CVE-2026-6322 · published 5 May 2026

CVE-2026-6322: Openjsf fast-uri interpretation conflict vulnerability

Openjsf · Fast Uri

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.

7.5 CVSS 3.1 High EPSS 0.68% · top 49.8% CWE-436 · Interpretation conflictCWE-140 · CWE-140
7.5CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
46References
10 Sep 2026Last modified by NVD

Description

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cna.openjsf.org/security-advisories.html Vendor Advisory
https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:25271
https://access.redhat.com/errata/RHSA-2026:25273
https://access.redhat.com/errata/RHSA-2026:26225
https://access.redhat.com/errata/RHSA-2026:26234
https://access.redhat.com/errata/RHSA-2026:28571
https://access.redhat.com/errata/RHSA-2026:29197
https://access.redhat.com/errata/RHSA-2026:29795
https://access.redhat.com/errata/RHSA-2026:29796
https://access.redhat.com/errata/RHSA-2026:29800
https://access.redhat.com/errata/RHSA-2026:29834
https://access.redhat.com/errata/RHSA-2026:30076
https://access.redhat.com/errata/RHSA-2026:33683
https://access.redhat.com/errata/RHSA-2026:34160
https://access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:34374
https://access.redhat.com/errata/RHSA-2026:34766
https://access.redhat.com/errata/RHSA-2026:34770
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36754
https://access.redhat.com/errata/RHSA-2026:37186
https://access.redhat.com/errata/RHSA-2026:37385
https://access.redhat.com/errata/RHSA-2026:37628
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:41951
https://access.redhat.com/errata/RHSA-2026:42078
https://access.redhat.com/errata/RHSA-2026:42142
https://access.redhat.com/errata/RHSA-2026:43038
https://access.redhat.com/errata/RHSA-2026:54395
https://access.redhat.com/errata/RHSA-2026:54555
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:56928
https://access.redhat.com/errata/RHSA-2026:56968
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:57487

Track CVE-2026-6322 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-84394Openjsf fast-uri interpretation conflict vulnerabilityfast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bra…EPSS 0.38%7.5CVE-2026-84292Openjsf fast-uri vulnerabilityfast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped b…EPSS 0.38%7.5CVE-2026-76172Openjsf fast-uri vulnerabilityfast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and se…EPSS 0.40%7.5CVE-2026-75931Openjsf fast-uri interpretation conflict vulnerabilityfast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative …EPSS 0.40%7.5CVE-2026-75975Openjsf fast-uri improper input validation vulnerabilityfast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing …EPSS 0.38%7.5CVE-2026-75899Openjsf fast-uri server-side request forgery (ssrf) vulnerabilityfast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time duri…EPSS 0.38%7.5CVE-2026-18446Openjsf fast-uri interpretation conflict vulnerabilityfast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash ba…EPSS 0.22%7.5CVE-2026-16221Openjsf fast-uri interpretation conflict vulnerabilityImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2026-6322), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.