CVE-2026-6321

Aliases:GHSA-q3j6-qgpj-74h6DEBIAN-CVE-2026-6321CGA-25fr-q854-mg67CGA-3435-5qxh-gw64CGA-5c59-rrmm-hqw2CGA-76r7-w6c9-c5mhCGA-7q62-p3j4-5rxcCGA-9768-jqmw-j3cgCGA-99hf-7hf3-3mr9CGA-c3hr-vmfc-qwc9CGA-gjc7-8f3r-8g2vCGA-gq25-hr33-c8vfCGA-gvmp-w8rf-q9xhCGA-mm89-983v-6vhqCGA-p8c6-7w67-524jCGA-2249-23m9-w6mxCGA-23vf-rp5j-mmvcCGA-25w8-f7jm-fpw9CGA-27m6-936c-2rv8CGA-287f-553c-7fxvCGA-28hg-v884-jxwvCGA-2949-h3jw-7hphCGA-2fcj-w6cj-p4mpCGA-2g65-hj56-wfqvCGA-2vp5-pm78-7fvxCGA-2wxf-9558-487xCGA-33c5-jc27-5hxgCGA-35vq-q33h-vf3vCGA-3c4h-fhg6-w2gwCGA-3g65-w763-4qm4CGA-3jgr-x585-8fc7CGA-3q5x-9hfw-j28qCGA-42gq-hj57-6258CGA-43v4-49hg-78frCGA-48pj-448v-m879CGA-48vh-8xqf-pv6qCGA-4924-23hm-pwfpCGA-4fpf-m2p6-cfpwCGA-4fph-pq8c-2hvcCGA-4gq3-x24f-r4f8CGA-4hhv-vmv9-jj27CGA-4jgg-44p3-fx6xCGA-4jpj-p648-vrfjCGA-4v97-6wrp-vx67CGA-53cp-cccm-22wvCGA-545c-7826-cc78CGA-55x2-p383-vcjvCGA-57wj-9xvf-c6pfCGA-5876-v92g-8m4jCGA-59c8-34hf-gwvmCGA-5f59-87q8-7fcgCGA-5gp4-x77q-ghpcCGA-5hp3-pf56-262qCGA-5j2h-77hw-hvw3CGA-5q2g-8p4c-ww9hCGA-623w-pcqv-pggvCGA-634w-3m8r-vf2fCGA-63qj-72pj-866wCGA-63rj-5j88-2ghqCGA-65hw-vq29-gqr9CGA-6686-598f-w333CGA-66mv-rf5x-9p4mCGA-675c-g628-rq8mCGA-67x6-3p9w-p8h2CGA-686v-c5m4-22w4CGA-6cpm-qhx3-gphqCGA-6j7r-p82f-hwp7CGA-6pj3-f52c-5pffCGA-6rpr-8774-p8mwCGA-728j-5j3g-gpwhCGA-73rr-gqgr-qpc2CGA-74x9-xwpc-4c8gCGA-76c4-r59w-hvq2CGA-76h6-288m-4g56CGA-77rp-gvm7-93m9CGA-78pw-pvpw-24wcCGA-7ffq-7mg3-wpxxCGA-7m2w-r6gq-pfv7CGA-7m6h-fj67-qqgpCGA-7m9m-mqxc-525jCGA-7xfp-xffh-gx25CGA-7xgp-8627-9jfhCGA-84x4-5r5r-pqc3CGA-8h2p-x8h5-qrg4CGA-8jgf-xxrm-x845CGA-92m2-vh79-q93hCGA-997j-v6cx-wv7cCGA-9cvg-r3qx-jfmcCGA-9fwm-f795-rjf4CGA-9m3x-qhcx-j938CGA-c9jc-2g92-p622CGA-cfhp-5grw-4r7qCGA-cgfp-54q6-h46qCGA-cjmp-qh7q-r5jmCGA-crxp-rfv6-r252CGA-f264-pjv7-3wx4CGA-f3fp-6vmw-93mrCGA-f5gx-938w-rxq3CGA-f7mm-x84w-xwjcCGA-fcqv-4r57-wf6xCGA-ffv2-5385-fxmwCGA-fhww-qfqm-pqv3CGA-fppm-vwgf-8jcqCGA-gc4w-vc9r-64c6CGA-gcmh-gw98-ppjxCGA-gq23-gx2g-4c59CGA-grwr-wg6j-c74mCGA-gx3q-mrmf-xpw9CGA-h43w-m6p3-8864CGA-h55m-6j56-58f8CGA-h5xj-hjj4-9c97CGA-hc3g-3g5j-gh24CGA-hjfp-wjx6-wwjfCGA-hvp3-h6qf-35fmCGA-j57h-3fx3-hf48CGA-j65v-w49w-pwpcCGA-jc8f-49fv-8ph4CGA-jjx4-32w6-fq27CGA-jr2x-whwr-jxcgCGA-jrrp-cgg2-j3xhCGA-jwpq-62hm-2qwfCGA-jx4h-8r5w-9q99CGA-jxxx-x35q-cvc3CGA-m25h-wgmq-c575CGA-m2g9-f72w-5r86CGA-m2x4-mvch-h4grCGA-m346-vh93-h89qCGA-m78m-ppmc-8ffxCGA-m7cx-qhm4-7gprCGA-m93v-9hc6-q4x4CGA-m9c2-877g-78qfCGA-m9v3-54g7-pqvxCGA-mfx2-788h-gf7pCGA-mjg4-wc4g-gj9qCGA-mp2g-5cfh-6cqgCGA-mrjx-2mfv-j922CGA-mwh6-93vg-mv9vCGA-mwvc-f6cq-m6vhCGA-mxcf-gjpg-rpcpCGA-p63w-95pv-74xpCGA-pgq3-jf5w-3c98CGA-pm28-7cxv-vx9xCGA-ppwv-9v6m-wf27CGA-pq7f-vqcr-47rrCGA-pvxr-27pm-74r2CGA-q2c6-3m3q-8v76CGA-q3m3-pg9r-r4xvCGA-qghx-74fc-qrg2CGA-qp6w-m62p-66v2CGA-qv5f-3mwf-hjh9CGA-r2xr-j22c-8h2xCGA-r3c2-mwx8-phgmCGA-r4gv-828w-w3p6CGA-r5w2-g79x-2v85CGA-r827-cr4p-76g8CGA-rcqj-qxpp-qhxfCGA-rhxc-hw8r-7vg6CGA-rjg6-fpvg-5893CGA-rrpv-73h2-hrqjCGA-rrw8-jx3r-6mfrCGA-rwjx-h5w9-479jCGA-rxpc-w24j-4pqpCGA-v24x-52qx-9f53CGA-v32f-w5wv-5x29CGA-v87h-qqqc-vvcgCGA-v8v2-94w3-g994CGA-v952-w285-gfwhCGA-vm89-3vh9-vr4pCGA-vq5j-rgf4-3w3rCGA-vqwp-424q-hcvhCGA-vw2x-qj7f-8qpqCGA-vwqg-hmcj-pjg9CGA-w2f6-hxwg-4mc4CGA-w2fv-222c-xh6xCGA-w33f-7rx6-2rgxCGA-w3h5-m2fc-5m7vCGA-w472-j22j-762fCGA-w6r6-qx2q-9g32CGA-w6ww-grww-4xh4CGA-w78v-29wm-7jhpCGA-w8gp-cj2m-hr3gCGA-w9w4-wvxc-h7mgCGA-wh4q-3vfg-9h9mCGA-whrc-rrq5-j557CGA-wmwx-x383-p3rqCGA-wv5c-jcf2-c6ggCGA-wv83-p7vx-7wqpCGA-wxhj-7q57-fpppCGA-x25q-6vqf-8qp3CGA-x4j6-rmx5-jp8hCGA-x4xw-vc92-hcf6CGA-x62w-cjwp-qqw7CGA-x8hr-q874-3cffCGA-x95j-c525-8v3wCGA-x9w6-5mvc-r2g4CGA-xff2-vmx6-23wrCGA-xfxh-v9c6-5hjpCGA-xgjp-j9hv-j6w8CGA-xjjg-wh2c-hxj2CGA-xvmx-ffcf-3vf4CGA-xwhr-cwmv-xq2hCGA-3hrm-mfhw-753rCGA-wqv4-253x-5h8mCGA-27jj-ch84-qwv9CGA-cr49-jpj5-qx5vCGA-4666-r23q-cj2mCGA-7mh4-ccgm-f64gCGA-8q9x-2vxr-f36vCGA-j55m-qcpq-7v2p
Modified
Published: 04 May 2026, 19:31
Last modified:10 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.63% LOW
1% probability +0.11%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 May 2026, 19:31
Published
Vulnerability first disclosed
10 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.63% Percentile: 49%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.12

    < 3.12.7.2-r5

  • chainguardargo-workflows-ui-3.6

    < 3.6.19-r6

  • chainguardargo-workflows-ui-3.7

    < 3.7.14-r0 | < 3.7.14-r1

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddrupal-11.3

    < 11.3.13-r3

  • chainguardgitlab-rails-ce-18.1

    < 18.1.6-r36

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all | < 19.0.3-r1

  • chainguardgitlab-rails-ce-19.1

    < 19.1.7-r4

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    < 18.1.6-r15 | all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.1-r1 | < 19.1.6-r5

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardkeep-ui

    < 0.51.0-r6

  • chainguardkeep-ui-fips

    < 0.51.0-r6

  • chainguardkibana-8.17

    < 8.17.10-r21

  • chainguardkibana-8.17-bitnami

    < 8.17.10-r21

  • chainguardkibana-8.17-iamguarded

    < 8.17.10-r21

  • chainguardkibana-8.19

    < 8.19.15-r0

  • chainguardkibana-8.19-bitnami

    < 8.19.15-r0

  • chainguardkibana-8.19-iamguarded

    < 8.19.15-r0

  • chainguardkibana-9.0

    < 9.0.8-r25

  • chainguardkibana-9.0-bitnami

    < 9.0.8-r25

  • chainguardkibana-9.0-iamguarded

    < 9.0.8-r25

  • chainguardkibana-9.1

    < 9.1.10-r17

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r17

  • chainguardkibana-9.2

    < 9.2.8-r3

Showing first 50 affected entries in server-rendered view.

References (32)