CVE-2026-6321General(openjsf / fast-uri)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openjsf fast-uri systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-uri

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-04); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
fast-uri

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-04: 3Mentions · 2026-05-05: 1Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-04: 3Technical Details · 2026-05-05: 1Technical Details · 2026-05-25: 105-0405-0505-25
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-043
General2Patch1
2026-05-051
Disclosure1
2026-05-251
Patch1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-6321 fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was tr… https://www.cve.org/CVERecord?id=CVE-2026-6321

    Post summary

    CVE‑2026‑6321 involves an URI normalization flaw in fast‑uri, but the text offers no PoC, exploit details, known exploitation, patch info, or false‑positive claim.

    00010168
    57.4K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in fast-uri@3.1.1 just released! Patches CVE-2026-6321 — fast-uri vulnerable to path traversal via percent-encoded dot segments https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6

    Post summary

    Fastify released fast-uri 3.1.1 to patch CVE-2026-6321, a path traversal flaw involving percent‑encoded dot segments. The advisory provides the version and indicates a fix without detailing exploitation or PoC.

    00010149
    5.6K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-6321 (CVSS 7.5) fast-uri &lt;=3.1.0 vulnerable to path traversal via percent-encoded separators. Attackers can bypass path-based security controls. Patch: Update to v3.1.1+ #CVE #Vulnerability #PatchNow https://t.co/vHYWxrJ02i

    Post summary

    CVE-2026-6321 is a path traversal flaw in fast‑uri <=3.1.0 that bypasses security controls; updating to 3.1.1+ patches the issue.

    0000049
    30 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6321 Path Traversal Vulnerability in fast-uri Versions 3.1.0 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6321

    Post summary

    The text announces a path traversal vulnerability in fast-uri 3.1.0 and earlier, with no provided exploit details, patch information, or evidence of active exploitation.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6321 fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was tr… https://www.cve.org/CVERecord?id=CVE-2026-6321 ----- Traducción: CVE-2026-6321 rut… http://infoflow.cloud`

    Post summary

    The post outlines technical aspects of CVE-2026-6321 regarding path decoding but does not mention PoCs, exploits, patches, or active attacks.

    0000029
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsffast-uri-node.js-

Explore more