PT-2026-36919 · Npm+1 · Fast-Uri+1

·

CVE-2026-6321

·

Published

2026-05-04

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions fast-uri versions prior to 3.1.1
Description The normalize() and equal() functions decode percent-encoded path separators and dot segments before performing dot-segment removal. This causes encoded path data to be treated as actual slashes and parent-directory references, allowing distinct URIs to collapse into the same normalized path. Consequently, applications using these functions to enforce path-based policies on attacker-controlled URLs may be bypassed, as a path appearing confined under an allowed prefix can normalize to a different location.
Recommendations Update to version 3.1.1 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BE61221
CLEANSTART-2026-LC05413
CVE-2026-6321
GHSA-Q3J6-QGPJ-74H6
OPENSUSE-SU-2026:10750-1
OPENSUSE-SU-2026:11178-1
OPENSUSE-SU-2026:21173-1
OPENSUSE-SU-2026:21266-1
RHSA-2026:42078
RHSA-2026:42079

Affected Products

Confluence
Fast-Uri