Fast-URI Path Normalization Bypass Fast-URI <=3.1.0
CVE-2026-6321 Published on May 4, 2026

fast-uri vulnerable to path traversal via percent-encoded dot segments
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.

NVD

Vulnerability Analysis

CVE-2026-6321 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

What is a Directory traversal Vulnerability?

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CVE-2026-6321 has been classified to as a Directory traversal vulnerability or weakness.


Products Associated with CVE-2026-6321

Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

fast-uri: Red Hat HawtIO HawtIO 4.4.0: Red Hat Ansible Automation Platform 2.5 for RHEL 8: Red Hat Ansible Automation Platform 2.5 for RHEL 9: Red Hat Ansible Automation Platform 2.6 for RHEL 9: Red Hat Enterprise Linux 10: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Network Observability (NETOBSERV) 1.12.0: Red Hat Ansible Automation Platform 2.5: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Developer Hub 1.8: Red Hat Developer Hub 1.9: Red Hat Discovery 2: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.16: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.18: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat Openshift Data Foundation 4.19: Red Hat OpenShift Dev Spaces 3.28: Red Hat Satellite 6.18: Red Hat Confidential Compute Attestation: Red Hat Cryostat 4: Red Hat OpenShift Pipelines: Red Hat OpenShift Pipelines: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Build of Podman Desktop: Red Hat Build of Podman Desktop: Red Hat Build of Podman Desktop - Tech Preview: Red Hat Data Grid 8: Red Hat Developer Hub: Red Hat Enterprise Linux 10: Red Hat Enterprise Linux 9: Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift Container Platform 4: Red Hat Satellite 6: Red Hat Satellite 6: Red Hat Satellite 6: Red Hat streams for Apache Kafka 2: Red Hat streams for Apache Kafka 3:

Exploit Probability

EPSS
0.40%
Percentile
31.36%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.