THREAT OPS › Threat News › [NVD] CVE-2026-18446 (HIGH 7.5) — fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authorit
[NVD] CVE-2026-18446 (HIGH 7.5) — fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authorit
CVE-2026-18446 CVSS: 7.5 HIGH Published: 2026-07-31T15:16:27.983
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL pa
Indicators of compromise
- CVE-2026-18446cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18446