CVE-2026-42371
published 2026-04-27CVE-2026-42371: uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
PriorityP416medium5.1CVSS 3.1
AVLACHPRNUINSUCNINAH
EPSS
0.17%
6.9th percentile
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uriparser | uriparser | < 1.0.1 | 1.0.1 |
| uriparser_project | uriparser | < 1.0.1 | 1.0.1 |
| uriparser_project | uriparser | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
uriparser up to 1.0.0 URI numeric truncation error (Nessus ID 310600)
vuldb·2026-04-29·CVSS 5.1
CVE-2026-42371 [MEDIUM] uriparser up to 1.0.0 URI numeric truncation error (Nessus ID 310600)
A vulnerability was found in uriparser up to 1.0.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component URI Handler. The manipulation leads to numeric truncation error.
This vulnerability is uniquely identified as CVE-2026-42371. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-3f6w-rmcx-pgmh: uriparser before 1
ghsa_unreviewed·2026-04-27
CVE-2026-42371 [MEDIUM] CWE-197 GHSA-3f6w-rmcx-pgmh: uriparser before 1
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
Red Hat
uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs
vendor_redhat·2026-04-27·CVSS 5.1
CVE-2026-42371 [MEDIUM] CWE-190 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs
uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs
A flaw was found in uriparser. This vulnerability occurs due to numeric truncation in text range comparison when an application processes extremely long Uniform Resource Identifiers (URIs), specifically those with lengths in gigabytes. A local attacker could exploit this flaw by providing a malformed, excessively long URI, leading to a Denial of Service (DoS) condition where the application becomes unavailable.
Package: uriparser (Red Hat Enterprise Linux 7) - Fix deferred
Package: uriparser (Red Hat Enterprise Linux AI (RHEL AI) 3) - Fix deferred
Package: uriparser (Red Hat Hardened Images) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [fedora-all]
bugzilla·2026-04-27·CVSS 5.1
CVE-2026-42371 [MEDIUM] CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [fedora-all]
CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs
bugzilla·2026-04-27·CVSS 5.1
CVE-2026-42371 [MEDIUM] CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs
CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
Bugzilla
CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [epel-all]
bugzilla·2026-04-27·CVSS 5.1
CVE-2026-42371 [MEDIUM] CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [epel-all]
CVE-2026-42371 uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-04-27
Published