CVE-2026-93751
EUVD-2026-8325618.09.2026, 18:18
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| garycourt | uri-js | 𝑥 ≤ 4.4.1 | CNA |
Debian Releases
Common Weakness Enumeration