---
id: CVE-2026-18446
title: >-
  fast-uri: fast-uri: Host confusion vulnerability via backslash in URI
  authority (CVE-2026-18446)
summary: >-
  A flaw was found in fast-uri. This vulnerability arises because fast-uri
  incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is
  used in place of a forward slash to introduce the authority component. This
  discrepancy wit…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
cwe:
  - CWE-1289
  - CWE-436
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - openshift_serverless
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - cryostat 4
  - migration_toolkit_for_applications 8
  - migration_toolkit_for_containers
  - multicluster_engine_for_kubernetes
  - network_observability_operator
  - openshift_lightspeed
  - 3scale_api_management_platform 2
  - advanced_cluster_management_for_kubernetes 2
  - amq_broker 7
  - ansible_automation_platform 2
  - build_of_apache_camel_hawtio 4
  - build_of_apicurio_registry 3
  - connectivity_link 1
  - data_grid 8
  - discovery 2
  - edge_manager 1
  - enterprise_linux 10
  - enterprise_linux 9
  - openshift_data_foundation 4
  - quay 3
  - satellite 6
  - secrets_management_console_for_red_hat_openshift
  - self_service_automation_portal 2
  - hardened_images
  - openshift_container_platform 4.16
patched:
  - hardened_images
  - openshift_container_platform 4.16
published: '2026-07-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T08:29:03+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18446.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18446.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18446'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2509801'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18446'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18446'
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: >-
      https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7
  - url: 'https://access.redhat.com/errata/RHSA-2026:49401'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62550'
  - url: >-
      https://github.com/fastify/fast-uri/commit/f3c6c905f47831007490f466c5945012e905cc52
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v4.1.2'
  - url: 'https://github.com/advisories/GHSA-7p8r-x3mc-p8w7'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00221
epssPercentile: 0.11293
aliases:
  - GHSA-7p8r-x3mc-p8w7
ecosystem: npm
ingestedAt: '2026-08-03T19:29:00.364Z'
---

## Overview

A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy with Node's native WHATWG URL parser can lead to host confusion. A remote attacker could exploit this to bypass security policies, such as allowlists or Server-Side Request Forgery (SSRF) filters, potentially redirecting applications to unintended hosts.

## Vendor advisories

- **RHSA-2026:49401** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:49401)
- **RHSA-2026:49387** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:49387)
- **RHSA-2026:62550** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62550)
- **Red Hat VEX** · Important · affected: OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Cryostat 4, Migration Toolkit for Applications 8, … · no fix planned: OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18446.json)

**fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority** — rated Important by Red Hat. Released 2026-07-31, updated 2026-09-10.

Affected:

- OpenShift Serverless
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Cryostat 4
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multicluster Engine for Kubernetes
- Network Observability Operator
- OpenShift Lightspeed
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Connectivity Link 1
- Red Hat Data Grid 8
- Red Hat Discovery 2
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Openshift Data Foundation 4
- Red Hat Quay 3
- Red Hat Satellite 6
- Secrets Management Console for Red Hat OpenShift
- Self-service automation portal 2

Fixed:

- Red Hat Hardened Images
- Red Hat OpenShift Container Platform 4.16

No fix planned:

- OpenShift Serverless
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat OpenShift Container Platform 4.16
- OpenShift Pipelines
- OpenShift Serverless
- Red Hat Build of Podman Desktop
- Red Hat Developer Hub
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Dev Spaces

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49401
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49387
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as fol… https://access.redhat.com/errata/RHSA-2026:62550

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-18446)

Affected packages:

- `fast-uri < 2.4.4`
- `fast-uri >= 3.0.0, < 3.1.5`
- `fast-uri >= 4.0.0, < 4.1.2`

Patched in:

- `fast-uri 2.4.4`
- `fast-uri 3.1.5`
- `fast-uri 4.1.2`

Source: https://github.com/advisories/GHSA-7p8r-x3mc-p8w7
