CVE-2026-6322Openjsf · Fast-uri
Vulnerability data via NVD (ingested)
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-6322product:"Openjsf Fast-uri"http.html:"Fast-uri"More intel sources (5)
vuln:CVE-2026-6322vulnerabilities.cve_id: CVE-2026-6322CVE-2026-6322CVE-2026-6322"CVE-2026-6322" exploit -site:nvd.nist.gov