CVE-2026-44928
published 2026-05-08CVE-2026-44928: In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.21%
11.4th percentile
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uriparser | uriparser | < 1.0.2 | 1.0.2 |
| uriparser_project | uriparser | < 1.0.2 | 1.0.2 |
| uriparser_project | uriparser | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
uriparser: uriparser: Incorrect URI comparison leading to integrity issues
vendor_redhat·2026-05-08·CVSS 5.3
CVE-2026-44928 [MEDIUM] CWE-1025 uriparser: uriparser: Incorrect URI comparison leading to integrity issues
uriparser: uriparser: Incorrect URI comparison leading to integrity issues
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
A flaw was found in uriparser. The `EqualsUri` function can incorrectly identify distinct Uniform Resource Identifiers (URIs) as identical. This misclassification can lead to improper URI handling within applications that use uriparser, potentially compromising data integrity.
Statement: A Moderate integrity flaw was found in uriparser, where the `EqualsUri` function can incorrectly identify distinct URIs as identical. This misclassification can lead to improper URI handling within applications utilizing uriparser, potentially compromising data integrity in Red Hat products that rely on accurate URI differentiation
GHSA
GHSA-xw5w-xhjv-gf29: In uriparser before 1
ghsa_unreviewed·2026-05-08
CVE-2026-44928 [LOW] CWE-670 GHSA-xw5w-xhjv-gf29: In uriparser before 1
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues [fedora-all]
bugzilla·2026-06-16·CVSS 5.3
CVE-2026-44928 [MEDIUM] CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues [fedora-all]
CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues [epel-all]
bugzilla·2026-06-16·CVSS 5.3
CVE-2026-44928 [MEDIUM] CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues [epel-all]
CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues
bugzilla·2026-05-08·CVSS 5.3
CVE-2026-44928 [MEDIUM] CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues
CVE-2026-44928 uriparser: uriparser: Incorrect URI comparison leading to integrity issues
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
2026-05-08
Published