CVE-2025-67899
published 2025-12-14CVE-2025-67899: uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
PriorityP410low2.9CVSS 3.1
AVLACHPRNUINSUCNINAL
EPSS
0.12%
2.4th percentile
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | uriparser | — | — |
| ubuntu | uriparser | — | — |
| uriparser_project | uriparser | <= 0.9.9 | — |
CVSS provenance
nvdv3.12.9LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
osv2.9LOW
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h2vr-rqqp-xv8m: uriparser through 0
ghsa_unreviewed·2025-12-15
CVE-2025-67899 [LOW] CWE-674 GHSA-h2vr-rqqp-xv8m: uriparser through 0
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
OSV
CVE-2025-67899: uriparser through 0
osv·2025-12-14·CVSS 2.9
CVE-2025-67899 [LOW] CVE-2025-67899: uriparser through 0
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
Ubuntu
uriparser vulnerability
vendor_ubuntu·2026-06-09
CVE-2025-67899 uriparser vulnerability
Title: uriparser vulnerability
Summary: uriparser could be made to crash if it received specially crafted
input.
It was discovered that uriparser incorrectly handled certain URI strings.
An attacker could possibly use this issue to cause uriparser to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
uriparser: uriparser: Unbounded recursion and stack consumption via large input
vendor_redhat·2025-12-14·CVSS 2.9
CVE-2025-67899 [LOW] CWE-674 uriparser: uriparser: Unbounded recursion and stack consumption via large input
uriparser: uriparser: Unbounded recursion and stack consumption via large input
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
A flaw was found in uriparser. This vulnerability allows unbounded recursion and stack consumption via large input containing many commas.
Statement: This vulnerability is rated Low for Red Hat because it requires local access and a specially crafted URI to trigger unbounded recursion, leading to stack consumption. The attack complexity is high, limiting its practical impact in most Red Hat deployments.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria compr
Debian
CVE-2025-67899: uriparser - uriparser through 0.9.9 allows unbounded recursion and stack consumption, as dem...
vendor_debian·2025·CVSS 2.9
CVE-2025-67899 [LOW] CVE-2025-67899: uriparser - uriparser through 0.9.9 allows unbounded recursion and stack consumption, as dem...
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-67899 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2025-67899 [LOW] CVE-2025-67899 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67899 :
Linux Debian vulnerability analysis and mitigation
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
Source : NVD
## 2.9
Score
Published December 14, 2025
Severity LOW
CNA Score 2.9
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mingw64-uriparser
uriparser-debuginfo
Sources
NVD
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Dec 16, 2025
Debian 14 Severity LOW No Fix Added at: Dec 16, 2025
Echo Severity LOW Has Fix Added at: Dec
Bugzilla
CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-8]
bugzilla·2025-12-17·CVSS 2.9
CVE-2025-67899 [LOW] CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-8]
CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-db33d2ec22 (uriparser-1.0.2-1.el8) has been submitted as an update to Fedora EPEL 8.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-db33d2ec22
---
FEDORA-
Bugzilla
CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-9]
bugzilla·2025-12-17·CVSS 2.9
CVE-2025-67899 [LOW] CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-9]
CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-eceb3c3c56 (uriparser-1.0.2-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-eceb3c3c56
---
FEDORA-
Bugzilla
CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-10]
bugzilla·2025-12-17·CVSS 2.9
CVE-2025-67899 [LOW] CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-10]
CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-b164c650f2 (uriparser-1.0.2-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b164c650f2
---
2025-12-14
Published