CVE-2026-44927
published 2026-05-08CVE-2026-44927: In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.21%
11.5th percentile
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uriparser | uriparser | < 1.0.2 | 1.0.2 |
| uriparser_project | uriparser | < 1.0.2 | 1.0.2 |
| uriparser_project | uriparser | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmxg-5w57-j63q: In uriparser before 1
ghsa_unreviewed·2026-05-08
CVE-2026-44927 [LOW] CWE-197 GHSA-gmxg-5w57-j63q: In uriparser before 1
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
Red Hat
uriparser: uriparser: Data integrity issue due to pointer truncation
vendor_redhat·2026-05-08·CVSS 5.3
CVE-2026-44927 [MEDIUM] CWE-681 uriparser: uriparser: Data integrity issue due to pointer truncation
uriparser: uriparser: Data integrity issue due to pointer truncation
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
A flaw was found in uriparser. This vulnerability involves pointer difference truncation, where calculations involving memory addresses are incorrectly shortened. This could lead to minor data integrity issues within the application. Exploitation of this flaw requires local access to the system and is complex.
Statement: This flaw in uriparser has a Low impact, as it requires local access to the system and is complex to exploit. The pointer difference truncation could lead to minor data integrity issues within applications utilizing uriparser.
Mitigation: Mitigation for this issue is either not available or the currently availa
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation [epel-all]
bugzilla·2026-06-15·CVSS 5.3
CVE-2026-44927 [MEDIUM] CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation [epel-all]
CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation [fedora-all]
bugzilla·2026-06-15·CVSS 5.3
CVE-2026-44927 [MEDIUM] CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation [fedora-all]
CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This is fixed by uriparser-1.0.2 which is in all current Fedora releases.
Bugzilla
CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation
bugzilla·2026-05-08·CVSS 5.3
CVE-2026-44927 [MEDIUM] CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation
CVE-2026-44927 uriparser: uriparser: Data integrity issue due to pointer truncation
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
2026-05-08
Published