Threats Tagged 'cve-2026-18446'
View all threats tagged with 'cve-2026-18446'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-18446'
Click on any threat for detailed analysis and mitigation recommendations
fast-uri vulnerable to host confusion via backslash authority introducer (CVE-2026-18446)CVE-2026-18446 0 fast-uri versions prior to 2.4.4, 3.1.5, and 4.1.2 improperly parse URIs that use backslash sequences (e.g., \\) as authority introducers instead of the standard double slash (//). This causes a host confusion vulnerability where fast-uri treats the backslash sequence and subsequent text as part of the path, while Node's native WHATWG URL parser treats backslashes as slashes and extracts a different host. This discrepancy can lead to bypassing host-based security policies such as allowlists, denylists, SSRF filtering, redirect validation, or proxy routing. The vulnerability is tracked as CVE-2026-18446 and has a high severity with a CVSS score of 7.5. Join the discussion | GCVE Database | 08/03/2026, 19:16:43 UTC Added: 08/03/2026, 21:21:24 UTC |
Showing 1 to 1 of 1 result