---
id: CVE-2026-75975
title: >-
  fast-uri: fast-uri: Server-side request forgery via malformed IPv6
  normalization (CVE-2026-75975)
summary: >-
  A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for
  bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing
  invalid trailing text in an authority to be silently discarded. This can lead
  to a mal…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
cwe:
  - CWE-918
  - CWE-20
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - multicluster_engine_for_kubernetes
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_serverless
  - ansible_automation_platform 2
  - build_of_apicurio_registry 3
  - build_of_podman_desktop
  - data_grid 8
  - developer_hub
  - enterprise_linux 10
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_dev_spaces
  - satellite 6
  - secrets_management_console_for_red_hat_openshift
  - self_service_automation_portal 2
  - enterprise_linux_appstream_v_10
  - network_observability_netobserv 1.12.3
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_management_for_kubernetes 2.17
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - developer_hub 1.9
  - discovery 2
  - edge_manager 1.1
  - edge_manager 1.2
  - hardened_images
  - migration_toolkit 1.8
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_dev_spaces 3.30
  - satellite 6.18
  - satellite 6.19
patched:
  - enterprise_linux_appstream_v_10
  - network_observability_netobserv 1.12.3
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_management_for_kubernetes 2.17
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - developer_hub 1.9
  - discovery 2
  - edge_manager 1.1
  - edge_manager 1.2
  - hardened_images
  - migration_toolkit 1.8
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_dev_spaces 3.30
  - satellite 6.18
  - satellite 6.19
published: '2026-08-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:05:43+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75975.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75975.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-75975'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2521779'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-75975'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75975'
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: >-
      https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc
  - url: 'https://access.redhat.com/errata/RHSA-2026:71543'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70593'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67542'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67543'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65118'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65155'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69248'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61783'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68044'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68253'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68006'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68254'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60866'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60855'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60856'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68681'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68547'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68553'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68754'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68762'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68756'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68766'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68765'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68748'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68750'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68747'
  - url: >-
      https://github.com/fastify/fast-uri/commit/3728465caacef4b16bc84b7d14760f1c8fe41595
  - url: >-
      https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f
  - url: >-
      https://github.com/fastify/fast-uri/commit/9161eded1ff55fad9d9714c6ad6c0f0283547799
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v2.4.5'
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v3.1.6'
  - url: 'https://github.com/fastify/fast-uri/releases/tag/v4.1.3'
  - url: 'https://github.com/advisories/GHSA-f65p-4m7j-42xc'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00377
epssPercentile: 0.28869
aliases:
  - GHSA-f65p-4m7j-42xc
ecosystem: npm
ingestedAt: '2026-09-02T15:46:29.227Z'
---

## Overview

A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a malformed, attacker-controlled host being normalized into a different, valid IPv6 destination, such as a local or private IPv6 target. An application normalizing untrusted URLs before outbound requests, redirects, or proxy routing could be redirected, resulting in a server-side request forgery (SSRF) and address-policy bypass.

## Vendor advisories

- **RHSA-2026:71543** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71543)
- **RHSA-2026:70593** · Red Hat · fixed in: Network Observability (NETOBSERV) 1.12.3 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70593)
- **RHSA-2026:67542** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67542)
- **RHSA-2026:67543** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67543)
- **RHSA-2026:65118** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.1 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65118)
- **RHSA-2026:65155** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65155)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:69248** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69248)
- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)
- **RHSA-2026:68044** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68044)
- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, OpenShift Lightspeed, OpenShift Pipelines, OpenShift Serverless, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 3, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Data Grid 8, Secrets Management Console for Red Hat OpenShift, Multicluster Engine for Kubernetes, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75975.json)
- **RHSA-2026:68253** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68253)
- **RHSA-2026:68006** · Red Hat · fixed in: Red Hat Edge Manager 1.2 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68006)
- **RHSA-2026:68254** · Red Hat · fixed in: Red Hat Edge Manager 1.2 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68254)
- **RHSA-2026:60866** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:60866)
- **RHSA-2026:60855** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:60855)
- **RHSA-2026:60856** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:60856)

**fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization** — rated Important by Red Hat. Released 2026-08-24, updated 2026-09-24.

Affected:

- Multicluster Engine for Kubernetes
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Data Grid 8
- Red Hat Developer Hub
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift Dev Spaces
- Red Hat Satellite 6
- Secrets Management Console for Red Hat OpenShift
- Self-service automation portal 2

Fixed:

- Red Hat Enterprise Linux AppStream (v. 10)
- Network Observability (NETOBSERV) 1.12.3
- Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Ansible Automation Platform 2.1
- Red Hat Ansible Automation Platform 2.2
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.9
- Red Hat Discovery 2
- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2
- Red Hat Hardened Images
- Red Hat Migration Toolkit 1.8
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Red Hat Ansible Automation Platform 2
- Red Hat Data Grid 8
- Secrets Management Console for Red Hat OpenShift
- Multicluster Engine for Kubernetes
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Developer Hub
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift Dev Spaces
- Red Hat Satellite 6
- Self-service automation portal 2

Not affected:

- Network Observability (NETOBSERV) 1.12.3
- Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.9
- Red Hat Discovery 2
- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2
- Red Hat Migration Toolkit 1.8

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:71543
For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:70593
Before you apply this update, make sure all previously released errata
that are relevant to your system are applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67542

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connection…

## Package advisory (CVE-2026-75975)

Affected packages:

- `fast-uri >= 2.3.1, < 2.4.5`
- `fast-uri >= 3.0.0, < 3.1.6`
- `fast-uri >= 4.0.0, < 4.1.3`

Patched in:

- `fast-uri 2.4.5`
- `fast-uri 3.1.6`
- `fast-uri 4.1.3`

Source: https://github.com/advisories/GHSA-f65p-4m7j-42xc
