{"id":"CVE-2026-18446","title":"fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)","summary":"A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":["CWE-1289","CWE-436"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["openshift_serverless","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openshift_container_platform 4","cryostat 4","migration_toolkit_for_applications 8","migration_toolkit_for_containers","multicluster_engine_for_kubernetes","network_observability_operator","openshift_lightspeed","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","amq_broker 7","ansible_automation_platform 2","build_of_apache_camel_hawtio 4","build_of_apicurio_registry 3","connectivity_link 1","data_grid 8","discovery 2","edge_manager 1","enterprise_linux 10","enterprise_linux 9","openshift_data_foundation 4","quay 3","satellite 6","secrets_management_console_for_red_hat_openshift","self_service_automation_portal 2","hardened_images","openshift_container_platform 4.16"],"patched":["hardened_images","openshift_container_platform 4.16"],"published":"2026-07-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T08:29:03+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18446.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18446.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18446"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509801"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18446"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18446"},{"url":"https://cna.openjsf.org/security-advisories.html"},{"url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7"},{"url":"https://access.redhat.com/errata/RHSA-2026:49401"},{"url":"https://access.redhat.com/errata/RHSA-2026:49387"},{"url":"https://access.redhat.com/errata/RHSA-2026:62550"},{"url":"https://github.com/fastify/fast-uri/commit/f3c6c905f47831007490f466c5945012e905cc52"},{"url":"https://github.com/fastify/fast-uri/releases/tag/v4.1.2"},{"url":"https://github.com/advisories/GHSA-7p8r-x3mc-p8w7"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00221,"epssPercentile":0.12943,"aliases":["GHSA-7p8r-x3mc-p8w7"],"ecosystem":"npm","ingestedAt":"2026-08-03T19:29:00.364Z","slug":"CVE-2026-18446","body":"## Overview\n\nA flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy with Node's native WHATWG URL parser can lead to host confusion. A remote attacker could exploit this to bypass security policies, such as allowlists or Server-Side Request Forgery (SSRF) filters, potentially redirecting applications to unintended hosts.\n\n## Vendor advisories\n\n- **RHSA-2026:49401** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:49401)\n- **RHSA-2026:49387** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:49387)\n- **RHSA-2026:62550** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62550)\n- **Red Hat VEX** · Important · affected: OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Cryostat 4, Migration Toolkit for Applications 8, … · no fix planned: OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18446.json)\n\n**fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority** — rated Important by Red Hat. Released 2026-07-31, updated 2026-09-10.\n\nAffected:\n\n- OpenShift Serverless\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Cryostat 4\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- OpenShift Lightspeed\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 3\n- Red Hat Connectivity Link 1\n- Red Hat Data Grid 8\n- Red Hat Discovery 2\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Openshift Data Foundation 4\n- Red Hat Quay 3\n- Red Hat Satellite 6\n- Secrets Management Console for Red Hat OpenShift\n- Self-service automation portal 2\n\nFixed:\n\n- Red Hat Hardened Images\n- Red Hat OpenShift Container Platform 4.16\n\nNo fix planned:\n\n- OpenShift Serverless\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat OpenShift Container Platform 4.16\n- OpenShift Pipelines\n- OpenShift Serverless\n- Red Hat Build of Podman Desktop\n- Red Hat Developer Hub\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Spaces\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49401\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49387\nFor OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/\n\nYou may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.\n\nThe sha values for the release are as fol… https://access.redhat.com/errata/RHSA-2026:62550\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-18446)\n\nAffected packages:\n\n- `fast-uri < 2.4.4`\n- `fast-uri >= 3.0.0, < 3.1.5`\n- `fast-uri >= 4.0.0, < 4.1.2`\n\nPatched in:\n\n- `fast-uri 2.4.4`\n- `fast-uri 3.1.5`\n- `fast-uri 4.1.2`\n\nSource: https://github.com/advisories/GHSA-7p8r-x3mc-p8w7","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}