CVE-2026-18446High· 7.5▾ TwilightA flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
Last analysed / modified upstream
A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy with Node's native WHATWG URL parser can lead to host confusion. A remote attacker could exploit this to bypass security policies, such as allowlists or Server-Side Request Forgery (SSRF) filters, potentially redirecting applications to unintended hosts.
fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority — rated Important by Red Hat. Released 2026-07-31, updated 2026-09-10.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49401 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49387 For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/
You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.
The sha values for the release are as fol… https://access.redhat.com/errata/RHSA-2026:62550
Workarounds / mitigations:
Affected packages:
fast-uri < 2.4.4fast-uri >= 3.0.0, < 3.1.5fast-uri >= 4.0.0, < 4.1.2Patched in:
fast-uri 2.4.4fast-uri 3.1.5fast-uri 4.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75931High· 7.5fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931)
CVE-2026-18427High· 7.5@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass
CVE-2026-76172High· 7.5fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)
CVE-2026-75899High· 7.5fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
CVE-2026-75975High· 7.5fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)
CVE-2026-16221High· 7.5fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)