Interpretation Conflict in fast-uri - CVE-2026-18446
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass host-based policy checks and steer requests to an unintended destination.
The vulnerability exists due to interpretation conflict in the fast-uri URI parser when parsing references that use backslash-based authority introducers. A remote attacker can supply a specially crafted URL to bypass host-based policy checks and steer requests to an unintended destination.
The issue arises from inconsistent host extraction between fast-uri and Node's WHATWG URL handling for special schemes.
Affected software
ApplinX
Bitbucket Data Center
Bamboo Data Center
Jira Software Data Center
Jira Service Management Data Center
Informix Dynamic Server
How to mitigate CVE-2026-18446
Bitbucket Data Center - update to 9.4.23
Bamboo Data Center - update to 10.2.22
Jira Software Data Center - addressed in versions 10.3.25, 11.3.1
Jira Service Management Data Center - addressed in versions 10.3.25, 11.3.1
Informix Dynamic Server - addressed in versions 14.10.FC14W1, 15.0.1.16
External References
Related Security Bulletins
- Interpretation Conflict in fast-uri
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Bitbucket Data Center
- IBM ApplinX update for fast-uri
- Multiple vulnerabilities in IBM Informix Dynamic Server
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center