CVE-2026-6321
published 2026-05-04CVE-2026-6321: fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path…
high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | lightspeed-rhel8 | — | — |
| ansible-automation-platform-25 | lightspeed-rhel8 | — | — |
| ansible-automation-platform-26 | gateway-rhel9 | — | — |
| ansible-automation-platform-26 | lightspeed-rhel9 | — | — |
| ansible-automation-platform-tech-preview | mcp-server-rhel9 | — | — |
| ansible-automation-platform | automation-dashboard-rhel9 | — | — |
| devspaces | dashboard-rhel9 | — | — |
| discovery | discovery-ui-rhel9 | — | — |
| fast-uri | fast-uri | < 3.1.1 | 3.1.1 |
| fast-uri | fast-uri | >= 0 < 3.1.1 | 3.1.1 |
| network-observability | network-observability-console-plugin-rhel9 | — | — |
| odf4 | mcg-core-rhel9 | — | — |
| odf4 | ocs-client-console-rhel9 | — | — |
| odf4 | odf-console-rhel9 | — | — |
| odf4 | odf-multicluster-console-rhel9 | — | — |
| openjsf | fast-uri | < 3.1.1 | 3.1.1 |
| openshift-pipelines | pipelines-console-plugin-rhel8 | — | — |
| openshift-pipelines | pipelines-console-plugin-rhel9 | — | — |
| openshift-sandboxed-containers | osc-pccs | — | — |
| openshift4 | ose-monitoring-plugin-rhel9 | — | — |
| rhdesktop | rh-podman-desktop-ext-bootc-rhel10 | — | — |
| rhdh | backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor | — | — |
| rhdh | rhdh-hub-rhel9 | — | — |
| rhoai | odh-dashboard-rhel8 | — | — |
| rhoai | odh-dashboard-rhel9 | — | — |