{"id":"CVE-2026-16221","title":"fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)","summary":"A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrep…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":["CWE-807","CWE-436"],"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.22","affected":["migration_toolkit_for_applications 8","openshift_lightspeed","openshift_serverless","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openshift_container_platform 4","multicluster_engine_for_kubernetes","advanced_cluster_management_for_kubernetes 2","amq_broker 7","ansible_automation_platform 2","build_of_apicurio_registry 3","connectivity_link 1","data_grid 8","discovery 2","edge_manager 1","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","satellite 6","secrets_management_console_for_red_hat_openshift","self_service_automation_portal 2","hardened_images","migration_toolkit 1.8","openshift_data_foundation 4.22","quay 3.16","quay 3.9"],"patched":["hardened_images","migration_toolkit 1.8","openshift_data_foundation 4.22","quay 3.16","quay 3.9"],"published":"2026-07-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:24:34+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16221.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16221.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-16221"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502307"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16221"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16221"},{"url":"https://cna.openjsf.org/security-advisories.html"},{"url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx"},{"url":"https://access.redhat.com/errata/RHSA-2026:54518"},{"url":"https://access.redhat.com/errata/RHSA-2026:54517"},{"url":"https://access.redhat.com/errata/RHSA-2026:68681"},{"url":"https://access.redhat.com/errata/RHSA-2026:65130"},{"url":"https://access.redhat.com/errata/RHSA-2026:69255"},{"url":"https://access.redhat.com/errata/RHSA-2026:65514"},{"url":"https://github.com/fastify/fast-uri/commit/0542a216860fd70c062a4730e620576f62ded057"},{"url":"https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353"},{"url":"https://github.com/fastify/fast-uri/commit/9438266d6a7ded688c8bc7c4ba506da17f44a17b"},{"url":"https://github.com/fastify/fast-uri/releases/tag/v2.4.3"},{"url":"https://github.com/fastify/fast-uri/releases/tag/v3.1.4"},{"url":"https://github.com/fastify/fast-uri/releases/tag/v4.1.1"},{"url":"https://github.com/advisories/GHSA-v2hh-gcrm-f6hx"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00254,"epssPercentile":0.1719,"aliases":["GHSA-v2hh-gcrm-f6hx"],"ecosystem":"npm","ingestedAt":"2026-07-21T22:55:08.324Z","slug":"CVE-2026-16221","body":"## Overview\n\nA flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrepancy can cause applications that use fast-uri for security policy enforcement, such as allowlists or Server-Side Request Forgery (SSRF) filtering, to misidentify the intended host. Consequently, an attacker could bypass these security policies, potentially redirecting traffic to unintended internal or sensitive network destinations.\n\n## Vendor advisories\n\n- **RHSA-2026:54518** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54518)\n- **RHSA-2026:54517** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54517)\n- **RHSA-2026:68681** · Red Hat · fixed in: Red Hat Migration Toolkit 1.8 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68681)\n- **RHSA-2026:65130** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65130)\n- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)\n- **RHSA-2026:65514** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65514)\n- **Red Hat VEX** · Important · affected: Migration Toolkit for Applications 8, OpenShift Lightspeed, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · no fix planned: Migration Toolkit for Applications 8, OpenShift Lightspeed, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16221.json)\n\n**fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency** — rated Important by Red Hat. Released 2026-07-19, updated 2026-09-21.\n\nAffected:\n\n- Migration Toolkit for Applications 8\n- OpenShift Lightspeed\n- OpenShift Serverless\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Multicluster Engine for Kubernetes\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apicurio Registry 3\n- Red Hat Connectivity Link 1\n- Red Hat Data Grid 8\n- Red Hat Discovery 2\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Satellite 6\n- Secrets Management Console for Red Hat OpenShift\n- Self-service automation portal 2\n\nFixed:\n\n- Red Hat Hardened Images\n- Red Hat Migration Toolkit 1.8\n- Red Hat Openshift Data Foundation 4.22\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n\nNo fix planned:\n\n- Migration Toolkit for Applications 8\n- OpenShift Lightspeed\n- OpenShift Serverless\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Migration Toolkit 1.8\n- Red Hat Openshift Data Foundation 4.22\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n- Network Observability Operator\n- OpenShift Pipelines\n- OpenShift Serverless\n- Red Hat Build of Podman Desktop\n- Red Hat Developer Hub\n- Red Hat Hardened Images\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:54518\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:54517\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:68681\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-16221)\n\nAffected packages:\n\n- `fast-uri >= 2.3.1, <= 2.4.2`\n- `fast-uri >= 3.0.0, <= 3.1.3`\n- `fast-uri >= 4.0.0, <= 4.1.0`\n\nPatched in:\n\n- `fast-uri 2.4.3`\n- `fast-uri 3.1.4`\n- `fast-uri 4.1.1`\n\nSource: https://github.com/advisories/GHSA-v2hh-gcrm-f6hx","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}