What is CVE-2026-18446?
The fast-uri library only accepts a literal double forward slash (//) to recognize a URI authority. This vulnerability causes references using backslash-based introducers (such as \\, /\, or \/) to be parsed without an authority. It is recommended to update the fast-uri library to versions 4.1.2, 3.1.5, or 2.4.4.
Azərbaycanca: fast-uri kitabxanasında URI səlahiyyətinin tanınması üçün yalnız ikiqat düz slesh (//) qəbul edilir. Bu zəiflik, tərs slesh (\) əsaslı göstəricilərdən istifadə edən istinadların səlahiyyətsiz təhlil edilməsinə səbəb olur. fast-uri kitabxanasını 4.1.2, 3.1.5 və ya 2.4.4 versiyalarına yeniləmək tövsiyə olunur.
FAQ2
How can I protect against CVE-2026-18446?
You can protect against this vulnerability by updating the fast-uri library to versions 4.1.2, 3.1.5, or 2.4.4.
What is this vulnerability about?
The vulnerability is due to the fast-uri library only accepting a literal double forward slash (//), causing references with backslash-based introducers to be parsed without an authority.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.