PT-2026-95434 · Npm · Uri.Js
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
uri-js versions prior to 4.4.2
Description
A denial of service issue exists in the
removeDotSegments() function. The function enters an infinite loop when a path segment starts with Unicode line or paragraph separators. This can be triggered by calling removeDotSegments() directly or via the normalize() and resolve() functions when IRI (Internationalized Resource Identifier) handling is enabled. This behavior blocks the Node.js event loop indefinitely, eventually leading to heap exhaustion.Recommendations
Update uri-js to version 4.4.2 or later.
As a temporary workaround, avoid using the
removeDotSegments() function or the normalize() and resolve() functions with IRI handling enabled.Exploit
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uri.Js