Description
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.
Published: 2026-05-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v39h-62p7-jpjc fast-uri vulnerable to host confusion via percent-encoded authority delimiters
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:25271 cve-icon
https://access.redhat.com/errata/RHSA-2026:25273 cve-icon
https://access.redhat.com/errata/RHSA-2026:26225 cve-icon
https://access.redhat.com/errata/RHSA-2026:26234 cve-icon
https://access.redhat.com/errata/RHSA-2026:28571 cve-icon
https://access.redhat.com/errata/RHSA-2026:29197 cve-icon
https://access.redhat.com/errata/RHSA-2026:29795 cve-icon
https://access.redhat.com/errata/RHSA-2026:29796 cve-icon
https://access.redhat.com/errata/RHSA-2026:29800 cve-icon
https://access.redhat.com/errata/RHSA-2026:29834 cve-icon
https://access.redhat.com/errata/RHSA-2026:30076 cve-icon
https://access.redhat.com/errata/RHSA-2026:33683 cve-icon
https://access.redhat.com/errata/RHSA-2026:34160 cve-icon
https://access.redhat.com/errata/RHSA-2026:34342 cve-icon
https://access.redhat.com/errata/RHSA-2026:34374 cve-icon
https://access.redhat.com/errata/RHSA-2026:34766 cve-icon
https://access.redhat.com/errata/RHSA-2026:34770 cve-icon
https://access.redhat.com/errata/RHSA-2026:36651 cve-icon
https://access.redhat.com/errata/RHSA-2026:36754 cve-icon
https://access.redhat.com/errata/RHSA-2026:37186 cve-icon
https://access.redhat.com/errata/RHSA-2026:37385 cve-icon
https://access.redhat.com/errata/RHSA-2026:37628 cve-icon
https://access.redhat.com/errata/RHSA-2026:40118 cve-icon
https://access.redhat.com/errata/RHSA-2026:40945 cve-icon
https://access.redhat.com/errata/RHSA-2026:41066 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:41951 cve-icon
https://access.redhat.com/errata/RHSA-2026:42078 cve-icon
https://access.redhat.com/errata/RHSA-2026:42142 cve-icon
https://access.redhat.com/errata/RHSA-2026:43038 cve-icon
https://access.redhat.com/errata/RHSA-2026:54395 cve-icon
https://access.redhat.com/security/cve/CVE-2026-6322 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2466684 cve-icon
https://cna.openjsf.org/security-advisories.html cve-icon cve-icon
https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6322.json cve-icon
History

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Tue, 12 May 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openjsf
Openjsf fast-uri
CPEs cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*
Vendors & Products Openjsf
Openjsf fast-uri

Wed, 06 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Fast-uri
Fast-uri fast-uri
Vendors & Products Fast-uri
Fast-uri fast-uri

Tue, 05 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 May 2026 10:45:00 +0000

Type Values Removed Values Added
Description fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.
Title fast-uri vulnerable to host confusion via percent-encoded authority delimiters
Weaknesses CWE-436
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Fast-uri Fast-uri
Openjsf Fast-uri
cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-08-13T12:04:31.205Z

Reserved: 2026-04-14T20:28:09.160Z

Link: CVE-2026-6322

cve-icon Vulnrichment

Updated: 2026-08-13T12:04:31.205Z

cve-icon NVD

Status : Modified

Published: 2026-05-05T11:16:33.360

Modified: 2026-08-13T13:19:15.657

Link: CVE-2026-6322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T04:30:17Z

Weaknesses