CVE-2026-6322
ADVISORY - githubSummary
Impact
fast-uri v3.1.1 and earlier decodes percent-encoded authority delimiters (%40 as @, %3A as :) inside the host component and serializes them back as raw characters. This changes the URI structure, turning a hostname into userinfo plus a different host.
For example, http://trusted.com%40evil.com/ normalizes to http://trusted.com@evil.com/, which reparses as host evil.com with userinfo trusted.com.
Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the original URL appeared to contain.
Patches
Upgrade to fast-uri >= 3.1.2.
Workarounds
None. Upgrade to the patched version.
Common Weakness Enumeration (CWE)
Interpretation Conflict
Interpretation Conflict
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highDebian
-
CVSS SCORE
N/AlowUbuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-5vr9-c8qr-fqvg
-
minimos
MINI-3295-78cv-8c8c
-
minimos
MINI-3ch5-f9fg-5qp8
-
minimos
MINI-3pw3-frhj-pv3p
-
minimos
MINI-42cq-h6cq-xfr2
-
minimos
MINI-5488-h8vx-jg8x
-
minimos
MINI-68h2-8pv2-96rg
-
minimos
MINI-6ghw-h6v8-292r
-
minimos
MINI-9xxm-jwjc-42wj
-
minimos
MINI-ccrf-2qmw-9mf5
-
minimos
MINI-f8r3-3p4r-m872
-
minimos
MINI-fvwj-fhc5-6pgh
-
minimos
MINI-g4g3-m5f4-xp8m
-
minimos
MINI-g5h7-fx6q-rvr9
-
minimos
MINI-j328-j6jx-8mf6
-
minimos
MINI-pvmp-rxwq-qx2p
-
minimos
MINI-q3c8-jwfj-vh59
-
minimos
MINI-rcr9-hpj3-gw7p
-
minimos
MINI-rpm9-hmc7-7h3q
-
minimos
MINI-w4qq-57c5-qfm4
-
minimos
MINI-wg44-j4w5-c72f
-
minimos
MINI-wjg3-r6xh-jg3v
-