CVE-2026-6322

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.
References
Link Resource
https://cna.openjsf.org/security-advisories.html Vendor Advisory
https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:25271
https://access.redhat.com/errata/RHSA-2026:25273
https://access.redhat.com/errata/RHSA-2026:26225
https://access.redhat.com/errata/RHSA-2026:26234
https://access.redhat.com/errata/RHSA-2026:28571
https://access.redhat.com/errata/RHSA-2026:29197
https://access.redhat.com/errata/RHSA-2026:29795
https://access.redhat.com/errata/RHSA-2026:29796
https://access.redhat.com/errata/RHSA-2026:29800
https://access.redhat.com/errata/RHSA-2026:29834
https://access.redhat.com/errata/RHSA-2026:30076
https://access.redhat.com/errata/RHSA-2026:33683
https://access.redhat.com/errata/RHSA-2026:34160
https://access.redhat.com/errata/RHSA-2026:34342
https://access.redhat.com/errata/RHSA-2026:34374
https://access.redhat.com/errata/RHSA-2026:34766
https://access.redhat.com/errata/RHSA-2026:34770
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36754
https://access.redhat.com/errata/RHSA-2026:37186
https://access.redhat.com/errata/RHSA-2026:37385
https://access.redhat.com/errata/RHSA-2026:37628
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:41951
https://access.redhat.com/errata/RHSA-2026:42078
https://access.redhat.com/errata/RHSA-2026:42142
https://access.redhat.com/errata/RHSA-2026:43038
https://access.redhat.com/errata/RHSA-2026:54395
https://access.redhat.com/errata/RHSA-2026:54555
https://access.redhat.com/errata/RHSA-2026:56366
https://access.redhat.com/errata/RHSA-2026:56431
https://access.redhat.com/errata/RHSA-2026:56928
https://access.redhat.com/errata/RHSA-2026:56968
https://access.redhat.com/errata/RHSA-2026:57013
https://access.redhat.com/errata/RHSA-2026:57487
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:60855
https://access.redhat.com/errata/RHSA-2026:61783
https://access.redhat.com/security/cve/CVE-2026-6322
https://bugzilla.redhat.com/show_bug.cgi?id=2466684
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6322.json
Configurations

Configuration 1 (hide)

cpe:2.3:a:openjsf:fast-uri:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-05-05 11:16

Updated : 2026-09-10 13:20


NVD link : CVE-2026-6322

Mitre link : CVE-2026-6322

CVE.ORG link : CVE-2026-6322


JSON object : View

Products Affected

openjsf

  • fast-uri
CWE
CWE-436

Interpretation Conflict

CWE-140

Improper Neutralization of Delimiters