Garycourt

Uri-js

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 30.09.2026 19:45:07
  • Zuletzt bearbeitet 01.10.2026 02:12:10

A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack m...

  • EPSS 0.23%
  • Veröffentlicht 18.09.2026 17:51:36
  • Zuletzt bearbeitet 22.09.2026 20:25:55

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder val...

  • EPSS 0.46%
  • Veröffentlicht 18.09.2026 16:17:16
  • Zuletzt bearbeitet 22.09.2026 20:25:55

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments dire...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 04.06.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:15:40

uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do this, uri-js uses a regular expression, This regular expression is vulnerable to redos. This causes th...