CVE-2026-6321
ADVISORY - githubSummary
Impact
fast-uri v3.1.0 and earlier decodes percent-encoded path separators (%2F) and dot segments (%2E) before applying dot-segment removal in normalize() and equal(). This makes encoded path data behave like real / and .., so distinct URIs collapse onto the same normalized path.
For example, http://example.com/public/%2e%2e/admin normalizes to http://example.com/admin, and equal() considers them the same URI.
Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed. A path that looks confined under an allowed prefix can normalize to a different location.
Patches
Upgrade to fast-uri >= 3.1.1.
Workarounds
None. Upgrade to the patched version.
Common Weakness Enumeration (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highDebian
-
CVSS SCORE
N/AlowUbuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-9j5f-2hwm-8hfc
-
minimos
MINI-24vq-hhvw-x7gp
-
minimos
MINI-2559-95hr-c3wg
-
minimos
MINI-29xw-9782-pc26
-
minimos
MINI-343j-2w6h-763v
-
minimos
MINI-397f-9x7m-rx3r
-
minimos
MINI-46ph-8f96-22wx
-
minimos
MINI-5w75-56x2-grj2
-
minimos
MINI-6mrj-xvjx-pj5c
-
minimos
MINI-7v74-6m7h-3h89
-
minimos
MINI-c2q8-pcrx-vcxh
-
minimos
MINI-crq7-rw96-pf6c
-
minimos
MINI-cvmh-mhf7-29c6
-
minimos
MINI-fp7c-9852-9mqf
-
minimos
MINI-hmgx-7xcg-vq88
-
minimos
MINI-hwxv-wrh3-pc5h
-
minimos
MINI-r8w2-vj3j-pjch
-
minimos
MINI-rcc4-gfpp-phxc
-
minimos
MINI-wgv2-jxpc-x9pc
-
minimos
MINI-x7pr-qx6c-jm2p
-