CVE-2024-34402
published 2024-05-03CVE-2024-34402: An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer…
PriorityP346high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
1.23%
65.6th percentile
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | uriparser | < uriparser 0.9.8+dfsg-1 (forky) | uriparser 0.9.8+dfsg-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_uriparser_0.9.8-3_on_azure_linux_3.0 | — | — |
| uriparser_project | uriparser | <= 0.9.7 | — |
| uriparser_project | uriparser | >= 0 < 0.9.8+dfsg-1 | 0.9.8+dfsg-1 |
| uriparser_project | uriparser | >= 0 < 0.9.8+dfsg-1 | 0.9.8+dfsg-1 |
| uriparser_project | uriparser | >= 0 < 0.7.5-1ubuntu2+esm4 | 0.7.5-1ubuntu2+esm4 |
| uriparser_project | uriparser | >= 0 < 0.8.4-1ubuntu0.16.04.1~esm4 | 0.8.4-1ubuntu0.16.04.1~esm4 |
| uriparser_project | uriparser | >= 0 < 0.8.4-1+deb9u2ubuntu0.1+esm1 | 0.8.4-1+deb9u2ubuntu0.1+esm1 |
| uriparser_project | uriparser | >= 0 < 0.9.3-2ubuntu0.1~esm3 | 0.9.3-2ubuntu0.1~esm3 |
| uriparser_project | uriparser | >= 0 < 0.9.6+dfsg-1ubuntu0.1~esm1 | 0.9.6+dfsg-1ubuntu0.1~esm1 |
| uriparser_project | uriparser | >= 0 < 0.9.7+dfsg-2ubuntu0.1~esm1 | 0.9.7+dfsg-2ubuntu0.1~esm1 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv8.6HIGH
vendor_debian8.6HIGH
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
uriparser vulnerabilities
vendor_ubuntu·2025-03-19·CVSS 8.6
CVE-2024-34403 [HIGH] uriparser vulnerabilities
Title: uriparser vulnerabilities
Summary: Several security issues were fixed in uriparser.
It was discovered that uriparser did not correctly handle certain inputs,
which could lead to an integer overflow. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2024-34402, CVE-2024-34403)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
vendor_msrc·2024-05-14·CVSS 8.6
CVE-2024-34402 [HIGH] CWE-190 An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: M
Red Hat
uriparser: integer overflow via long keys or values in ComposeQueryEngine() in UriQuery.c
vendor_redhat·2024-05-03·CVSS 8.6
CVE-2024-34402 [HIGH] CWE-190 uriparser: integer overflow via long keys or values in ComposeQueryEngine() in UriQuery.c
uriparser: integer overflow via long keys or values in ComposeQueryEngine() in UriQuery.c
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
An integer overflow issue was found in Uriparser in the ComposeQueryEngine() function in UriQuery.c. This function computes the space needed for composing a query string. However, it encounters an integer overflow issue when handling large key or value lengths, potentially leading to incorrect memory allocations or operations due to malformed size calculations. This flaw allows attackers to crash the application, resulting in a denial of service.
Statement: We do not distribute this package in RHEL 8, 9, and 10. Additionally, RHEL 7
Debian
CVE-2024-34402: uriparser - An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQue...
vendor_debian·2024·CVSS 8.6
CVE-2024-34402 [HIGH] CVE-2024-34402: uriparser - An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQue...
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.9.8+dfsg-1)
sid: resolved (fixed in 0.9.8+dfsg-1)
trixie: resolved (fixed in 0.9.8+dfsg-1)
OSV
uriparser vulnerabilities
osv·2025-03-19·CVSS 8.6
CVE-2024-34402 [HIGH] uriparser vulnerabilities
uriparser vulnerabilities
It was discovered that uriparser did not correctly handle certain inputs,
which could lead to an integer overflow. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2024-34402, CVE-2024-34403)
OSV
CVE-2024-34402: An issue was discovered in uriparser through 0
osv·2024-05-03·CVSS 8.6
CVE-2024-34402 [HIGH] CVE-2024-34402: An issue was discovered in uriparser through 0
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
GHSA
GHSA-hwpw-xpj3-c397: An issue was discovered in uriparser through 0
ghsa_unreviewed·2024-05-03
CVE-2024-34402 [HIGH] CWE-190 GHSA-hwpw-xpj3-c397: An issue was discovered in uriparser through 0
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/05/06/1http://www.openwall.com/lists/oss-security/2024/05/06/3https://github.com/uriparser/uriparser/issues/183https://github.com/uriparser/uriparser/pull/185https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5R36L762D3KX3GA66OOPWW7M7KKDRXDP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CZ6KEUQXWCTYXGTBMZDD7CHJCYI52XY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UG4J7PD475LSCGCSHFU4GMU4TWLDSNW2/http://www.openwall.com/lists/oss-security/2024/05/06/1http://www.openwall.com/lists/oss-security/2024/05/06/3https://github.com/uriparser/uriparser/issues/183https://github.com/uriparser/uriparser/pull/185https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5R36L762D3KX3GA66OOPWW7M7KKDRXDP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CZ6KEUQXWCTYXGTBMZDD7CHJCYI52XY3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UG4J7PD475LSCGCSHFU4GMU4TWLDSNW2/https://lists.fedoraproject.org/archives/list/[email protected]/message/5R36L762D3KX3GA66OOPWW7M7KKDRXDP/https://lists.fedoraproject.org/archives/list/[email protected]/message/CZ6KEUQXWCTYXGTBMZDD7CHJCYI52XY3/
2024-05-03
Published