Path traversal in fast-uri - CVE-2026-6321

 

Path traversal in fast-uri - CVE-2026-6321

Published: July 22, 2026 / Updated: August 14, 2026


Vulnerability identifier: #VU139082
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6321
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass path-based policy checks.

The vulnerability exists due to path traversal in the normalize() and equal() functions when processing percent-encoded path separators and dot segments in attacker-controlled URLs. A remote attacker can supply a specially crafted URL to bypass path-based policy checks.

Applications that normalize or compare attacker-controlled URLs to enforce path-based policy are affected.


Affected software

fast-uri
Storage Sentinel Anomaly Scan Engine
MongoDB Enterprise Advanced with IBM
Data Cataloging
IBM Fusion HCI
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
Jira Software Data Center
Jira Service Management Data Center
Red Hat OpenShift Dev Spaces
Fedora
python-jupytext
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2026-6321

Install security update from vendor's website.

fast-uri - addressed in versions 2.4.1, 3.1.1
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
MongoDB Enterprise Advanced with IBM - update to 1.49.8
IBM Fusion HCI - update to 2.13.0
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Bitbucket Data Center - addressed in versions 9.4.22, 10.2.0, 10.3.0
Bamboo Data Center - update to 10.2.22
Jira Software Data Center - addressed in versions 10.3.23, 11.3.1
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.1
python-jupytext - addressed in versions 1.19.1-4.fc42, 1.19.1-4.fc43, 1.19.1-4.fc44
Data Cataloging - update to 2.5.3
Red Hat OpenShift Dev Spaces - update to 3.28.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.16.30, 4.18.24

External References

Related Security Bulletins