CVE-2026-93690
EUVD-2026-8298618.09.2026, 16:17
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| garycourt | uri-js | 𝑥 ≤ 4.4.1 | CNA |
Debian Releases
Common Weakness Enumeration
References