Skip to main content

Vendor/product archive

openjsf / fast-uri CVEs

Beta · best-effort

3 CVEs tagged to openjsf / fast-uri0 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-13676

Published Jun 29, 2026

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on th…

CVSS 7.5 · High
evidence mentions
18
Buzz score
43.9
Vendor/product tagsBeta · best-effort

CVE-2026-6322

Published May 5, 2026

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined a…

CVSS 7.5 · High
evidence mentions
35
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-6321

Published May 4, 2026

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like…

CVSS 7.5 · High
evidence mentions
22
Buzz score
44.5
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1