CVE-2026-103387
- EPSS 0.32%
- Veröffentlicht 30.09.2026 19:45:07
- Zuletzt bearbeitet 01.10.2026 02:12:10
A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack m...
CVE-2026-93751
- EPSS 0.23%
- Veröffentlicht 18.09.2026 17:51:36
- Zuletzt bearbeitet 22.09.2026 20:25:55
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder val...
CVE-2026-93690
- EPSS 0.46%
- Veröffentlicht 18.09.2026 16:17:16
- Zuletzt bearbeitet 22.09.2026 20:25:55
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments dire...
CVE-2017-16021
- EPSS 1.34%
- Veröffentlicht 04.06.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:15:40
uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do this, uri-js uses a regular expression, This regular expression is vulnerable to redos. This causes th...