PT-2026-95434 · Npm · Uri.Js

·

CVE-2026-93690

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions uri-js versions prior to 4.4.2
Description A denial of service issue exists in the removeDotSegments() function. The function enters an infinite loop when a path segment starts with Unicode line or paragraph separators. This can be triggered by calling removeDotSegments() directly or via the normalize() and resolve() functions when IRI (Internationalized Resource Identifier) handling is enabled. This behavior blocks the Node.js event loop indefinitely, eventually leading to heap exhaustion.
Recommendations Update uri-js to version 4.4.2 or later. As a temporary workaround, avoid using the removeDotSegments() function or the normalize() and resolve() functions with IRI handling enabled.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103439
CVE-2026-93690

Affected Products

Uri.Js