Source: node-uri-js
Version: 4.4.0+dfsg-10
Severity: important
Tags: security upstream
Forwarded: https://github.com/garycourt/uri-js/issues/105
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-uri-js.

CVE-2026-93690[0]:
| uri-js through 4.4.1 contains a denial of service vulnerability in
| the removeDotSegments function that loops infinitely when a path
| segment begins with Unicode line or paragraph separators. Attackers
| can trigger this by calling removeDotSegments directly or through
| normalize/resolve functions with IRI handling enabled, causing the
| Node.js event loop to block indefinitely until heap exhaustion.

TTBOMK no upstream fix exists yet at time of writing the bugreport.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93690
    https://www.cve.org/CVERecord?id=CVE-2026-93690
[1] https://github.com/garycourt/uri-js/issues/105

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to