Path traversal in fast-uri - CVE-2026-6321
Published: July 22, 2026 / Updated: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass path-based policy checks.
The vulnerability exists due to path traversal in the normalize() and equal() functions when processing percent-encoded path separators and dot segments in attacker-controlled URLs. A remote attacker can supply a specially crafted URL to bypass path-based policy checks.
Applications that normalize or compare attacker-controlled URLs to enforce path-based policy are affected.
Affected software
Storage Sentinel Anomaly Scan Engine
MongoDB Enterprise Advanced with IBM
Data Cataloging
IBM Fusion HCI
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
Jira Software Data Center
Jira Service Management Data Center
Red Hat OpenShift Dev Spaces
Fedora
python-jupytext
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2026-6321
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
MongoDB Enterprise Advanced with IBM - update to 1.49.8
IBM Fusion HCI - update to 2.13.0
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Bitbucket Data Center - addressed in versions 9.4.22, 10.2.0, 10.3.0
Bamboo Data Center - update to 10.2.22
Jira Software Data Center - addressed in versions 10.3.23, 11.3.1
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.1
python-jupytext - addressed in versions 1.19.1-4.fc42, 1.19.1-4.fc43, 1.19.1-4.fc44
Data Cataloging - update to 2.5.3
Red Hat OpenShift Dev Spaces - update to 3.28.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.16.30, 4.18.24
External References
Related Security Bulletins
- Multiple vulnerabilities in fast-uri
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.28
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- MongoDB Enterprise Advanced with IBM update for fast-uri
- IBM Fusion, IBM Fusion HCI, and IBM Fusion Data Cataloging update for fast-uri
- Fedora 44 update for python-jupytext
- Fedora 43 update for python-jupytext
- Fedora 42 update for python-jupytext
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in Bamboo Data Center