Uriparser Project
Uriparser Project Uriparser: vulnerabilidades y CVE
Uriparser Project Uriparser tiene 11 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses3
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44928 | Media (5.3) | 0.23% | — | 8 may 2026 | In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. |
| CVE-2026-44927 | Media (5.3) | 0.23% | — | 8 may 2026 | In uriparser before 1.0.2, there is pointer difference truncation to int in various places. |
| CVE-2026-42371 | Media (5.1) | 0.16% | — | 27 abr 2026 | uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. |
| CVE-2024-34403 | Media (5.9) | 1.3% | — | 3 may 2024 | An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string. |
| CVE-2024-34402 | Alta (8.6) | 1.2% | — | 3 may 2024 | An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow. |
| CVE-2021-46142 | Media (5.5) | 1.1% | — | 6 ene 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
| CVE-2021-46141 | Media (5.5) | 1.1% | — | 6 ene 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. |
| CVE-2018-20721 | Crítica (9.8) | 2.1% | — | 16 ene 2019 | URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address. |
| CVE-2018-19200 | Alta (7.5) | 2.5% | — | 12 nov 2018 | An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function. |
| CVE-2018-19199 | Crítica (9.8) | 2.3% | — | 12 nov 2018 | An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication. |
| CVE-2018-19198 | Crítica (9.8) | 2.4% | — | 12 nov 2018 | An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts. |