Interpretation Conflict in fast-uri - CVE-2026-6322
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass host-based security checks and route requests to an unintended authority.
The vulnerability exists due to interpretation conflict in the URI host component when processing percent-encoded authority delimiters. A remote attacker can supply a specially crafted URL to bypass host-based security checks and route requests to an unintended authority.
This issue can affect applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing.
Affected software
Storage Sentinel Anomaly Scan Engine
MongoDB Enterprise Advanced with IBM
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
Jira Software Data Center
Jira Service Management Data Center
Red Hat OpenShift Container Platform
JBoss Data Grid
How to mitigate CVE-2026-6322
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
MongoDB Enterprise Advanced with IBM - update to 1.49.8
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Bitbucket Data Center - addressed in versions 9.4.22, 10.2.0, 10.3.0
Bamboo Data Center - update to 10.2.22
Jira Software Data Center - addressed in versions 10.3.23, 11.3.1
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.19.37, 4.20.27, 4.20.29, 4.21.22, 4.21.23, 4.21.24, 4.22.3
JBoss Data Grid - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in fast-uri
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Interpretation Conflict in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Interpretation Conflict in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- MongoDB Enterprise Advanced with IBM update for fast-uri
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in Bamboo Data Center