Fast-URI Path Normalization Bypass Fast-URI <=3.1.0
CVE-2026-6321 Published on May 4, 2026
fast-uri vulnerable to path traversal via percent-encoded dot segments
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.
Vulnerability Analysis
CVE-2026-6321 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-6321 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-6321
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
fast-uri:- Before 3.1.1 is affected.
- Version 3.1.1 is unaffected.
- Version 0:2.5.20260715-1.el8ap and below * is unaffected.
- Version 0:2.5.20260715-1.el9ap and below * is unaffected.
- Version 0:2.6.11-1.el9ap and below * is unaffected.
- Version 0:1.1.1-1.el10_2 and below * is unaffected.
- Version 1782840519 and below * is unaffected.
- Version 1782839981 and below * is unaffected.
- Version 1782839193 and below * is unaffected.
- Version 1782838753 and below * is unaffected.
- Version 1782839279 and below * is unaffected.
- Version 1782840539 and below * is unaffected.
- Version 1782841925 and below * is unaffected.
- Version 1782838476 and below * is unaffected.
- Version 1782839996 and below * is unaffected.
- Version 1782839494 and below * is unaffected.
- Version 1780556069 and below * is unaffected.
- Version 1780082949 and below * is unaffected.
- Version 1779784904 and below * is unaffected.
- Version 1779783248 and below * is unaffected.
- Version 1779841586 and below * is unaffected.
- Version 1781187342 and below * is unaffected.
- Version 1779395188 and below * is unaffected.
- Version 1780467029 and below * is unaffected.
- Version 1780467147 and below * is unaffected.
- Version 1781183284 and below * is unaffected.
- Version 1781183499 and below * is unaffected.
- Version 1780663368 and below * is unaffected.
- Version 1781184121 and below * is unaffected.
- Version 1780663596 and below * is unaffected.
- Version 1781183713 and below * is unaffected.
- Version 1780663548 and below * is unaffected.
- Version 1781183811 and below * is unaffected.
- Version 1781184611 and below * is unaffected.
- Version 1780663638 and below * is unaffected.
- Version 1780663861 and below * is unaffected.
- Version 1780663920 and below * is unaffected.
- Version 1781184484 and below * is unaffected.
- Version 1780663886 and below * is unaffected.
- Version 1781184239 and below * is unaffected.
- Version 1780664089 and below * is unaffected.
- Version 1780664140 and below * is unaffected.
- Version 1781184468 and below * is unaffected.
- Version 1781555717 and below * is unaffected.
- Version 1781554936 and below * is unaffected.
- Version 1781555645 and below * is unaffected.
- Version 1781556009 and below * is unaffected.
- Version 1781558423 and below * is unaffected.
- Version 1781555708 and below * is unaffected.
- Version 1781557202 and below * is unaffected.
- Version 1781555679 and below * is unaffected.
- Version 1781557189 and below * is unaffected.
- Version 1781556534 and below * is unaffected.
- Version 1781556085 and below * is unaffected.
- Version 1781555971 and below * is unaffected.
- Version 1781557158 and below * is unaffected.
- Version 1781556690 and below * is unaffected.
- Version 1781558326 and below * is unaffected.
- Version 1781556544 and below * is unaffected.
- Version 1781556958 and below * is unaffected.
- Version 1781556901 and below * is unaffected.
- Version 1781557496 and below * is unaffected.
- Version 1778576707 and below * is unaffected.
- Version 1778576350 and below * is unaffected.
- Version 1778769574 and below * is unaffected.
- Version 1778576929 and below * is unaffected.
- Version 1778770148 and below * is unaffected.
- Version 1778576957 and below * is unaffected.
- Version 1779093256 and below * is unaffected.
- Version 1778577150 and below * is unaffected.
- Version 1778577175 and below * is unaffected.
- Version 1778577083 and below * is unaffected.
- Version 1778770362 and below * is unaffected.
- Version 1778577169 and below * is unaffected.
- Version 1778577201 and below * is unaffected.
- Version 1778577489 and below * is unaffected.
- Version 1778770439 and below * is unaffected.
- Version 1778577548 and below * is unaffected.
- Version 1778770127 and below * is unaffected.
- Version 1778577523 and below * is unaffected.
- Version 1778577519 and below * is unaffected.
- Version 1778577696 and below * is unaffected.
- Version 1780685176 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.