<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:40:28 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-6322 — fast-uri vulnerable to host confusion via percent-encoded authority delimiters</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-6322</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; fast-uri, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 10, Red Hat Cluster Observability Operator 1.5.0, Red Hat multicluster engine for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.16, Red Hat Ansible Automation Platform 2.6 and 46 more&lt;/p&gt;
&lt;p&gt;fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI&amp;#39;s authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions &amp;lt;= 3.1.1 are affected. Update to 3.1.2 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; fast-uri, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 10, Red Hat Cluster Observability Operator 1.5.0, Red Hat multicluster engine for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.16, Red Hat Ansible Automation Platform 2.6 and 46 more&lt;/p&gt;
&lt;p&gt;fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI&amp;#39;s authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions &amp;lt;= 3.1.1 are affected. Update to 3.1.2 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-6322</guid>
    </item>
  </channel>
</rss>
