PT-2026-99965 · Azure Linux · Jquery-Ujs
Published
2026-09-18
·
Updated
2026-09-18
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jquery-Ujs