CVE Vulnerabilities

CVE-2026-75899

Double Decoding of the Same Data

Published: Aug 24, 2026 | Modified: Sep 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a server-side request forgery and host-policy bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded percent signs. Users should upgrade to a patched version.

Weakness

The product decodes the same input twice, which can limit the effectiveness of any protection mechanism that occurs in between the decoding operations.

Affected Software

NameVendorStart VersionEnd Version
Fast-uriOpenjsf2.4.1 (including)2.4.5 (excluding)
Fast-uriOpenjsf3.1.2 (including)3.1.6 (excluding)
Fast-uriOpenjsf4.0.0 (including)4.1.3 (excluding)
Red Hat Enterprise Linux 10RedHatcockpit-image-builder-0:94.4-1.el10_2*
Red Hat Satellite 6.19 for RHEL 9RedHatforeman-0:3.18.0.14-1.el9sat*
Red Hat Satellite 6.19 for RHEL 9RedHatforeman-0:3.18.0.14-1.el9sat*
Red Hat Satellite 6.19 for RHEL 9RedHatforeman-0:3.18.0.14-1.el9sat*
Cluster Observability Operator 1.5.3RedHatcluster-observability-operator/troubleshooting-panel-console-plugin-rhel9:1790854494*
Multicluster engine for Kubernetes 2.11RedHatmulticluster-engine/console-mce-rhel9:1790133081*
Multicluster engine for Kubernetes 2.17RedHatmulticluster-engine/console-mce-rhel9:1790135323*
Network Observability (NETOBSERV) 1.12.3RedHatnetwork-observability/network-observability-console-plugin-pf5-rhel9:1789978780*
Network Observability (NETOBSERV) 1.12.3RedHatnetwork-observability/network-observability-console-plugin-rhel9:1789978277*
Red Hat Advanced Cluster Management for Kubernetes 2.16RedHatrhacm2/console-rhel9:1788880980*
Red Hat Advanced Cluster Management for Kubernetes 2.16RedHatrhacm2/console-rhel9:1788283612*
Red Hat Advanced Cluster Management for Kubernetes 2.17RedHatrhacm2/console-rhel9:1788883472*
Red Hat Ansible Automation Platform 2.1RedHatansible-automation-platform/automation-portal:1788775748*
Red Hat Ansible Automation Platform 2.2RedHatansible-automation-platform/automation-portal:1788783591*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-tech-preview/mcp-server-rhel9:1789669036*
Red Hat Ansible Automation Platform 2.7RedHatansible-automation-platform-27/mcp-server-rhel9:1788915736*
Red Hat Developer Hub 1.9RedHatrhdh/rhdh-hub-rhel9:1789554285*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1788206196*
Red Hat Edge Manager 1.1RedHatrhem/flightctl-ui-ocp-rhel10:1789486226*
Red Hat Edge Manager 1.1RedHatrhem/flightctl-ui-rhel10:1789486181*
Red Hat Edge Manager 1.1RedHatrhem/flightctl-ui-ocp-rhel9:1789486446*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-ocp-rhel10:1789485920*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-rhel10:1789488111*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-ocp-rhel9:1789486476*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-ui-rhel9:1789486750*
Red Hat Hardened ImagesRedHatgrafana13-1-main-13.1.3-0.3.hum1*
Red Hat Hardened ImagesRedHatgrafana13-2-main-13.2.0-0.1.2.hum1*
Red Hat Hardened ImagesRedHatgrafana12-4-main-12.4.9-0.4.hum1*
Red Hat Migration Toolkit 1.8RedHatrhmtc/openshift-migration-ui-rhel8:1789546373*
Red Hat OpenShift Container Platform 4.21RedHatopenshift4/nmstate-console-plugin-rhel9:1789592806*
Red Hat OpenShift Container Platform 4.22RedHatopenshift4/nmstate-console-plugin-rhel9:1789567849*
Red Hat OpenShift Dev Spaces 3.30RedHatdevspaces/dashboard-rhel9:1789162884*
Red Hat Satellite 6.18RedHatsatellite/iop-host-inventory-frontend-rhel9:1789613107*
Red Hat Satellite 6.18RedHatsatellite/iop-advisor-frontend-rhel9:1789659573*
Red Hat Satellite 6.18RedHatsatellite/iop-remediations-rhel9:1789615095*
Red Hat Satellite 6.18RedHatsatellite/iop-vulnerability-frontend-rhel9:1790483608*
Red Hat Satellite 6.19RedHatsatellite/iop-remediations-rhel9:1789615593*
Red Hat Satellite 6.19RedHatsatellite/iop-advisor-frontend-rhel9:1789659565*
Red Hat Satellite 6.19RedHatsatellite/iop-host-inventory-frontend-rhel9:1789624519*
Red Hat Satellite 6.19RedHatsatellite/iop-vulnerability-frontend-rhel9:1789660983*

Potential Mitigations

  • Assume all input is malicious. Use an “accept known good” input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
  • When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, “boat” may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as “red” or “blue.”
  • Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code’s environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.

References