CVE-2026-45822
published 2026-06-30CVE-2026-45822: decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls…
PriorityP338medium6.6CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSNAUYRUVDREMUAmber
EPSS
0.51%
42.3th percentile
decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | system-rhel7 | — | — |
| 3scale-amp2 | system-rhel8 | — | — |
| 3scale-amp2 | system-rhel9 | — | — |
| 3scale-amp21 | system | — | — |
| 3scale-amp22 | system | — | — |
| decode-uri-component_project | decode-uri-component | — | — |
| decode-uri-component_project | decode-uri-component | >= 0 < 0.5.0 | 0.5.0 |
| openshift-pipelines | pipelines-console-plugin-pf5-rhel9 | — | — |
| openshift-pipelines | pipelines-console-plugin-rhel9 | — | — |
| openshift4 | ose-console | — | — |
| openshift4 | ose-console-rhel9 | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| rhmtc | openshift-migration-ui-rhel8 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| samverschueren | decode-uri-component | >= 0.1.0 < 0.5.0 | 0.5.0 |
| satellite | iop-vulnerability-frontend-rhel9 | — | — |
CVSS provenance
nvdv4.06.6MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
ghsa·2026-08-31
CVE-2026-45822 [MEDIUM] CWE-1176 decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
### Impact
An attacker who can supply input to `decodeUriComponent()` (directly or via a dependency that uses this package on URL/query/path data) can cause excessive CPU usage and application unresponsiveness. This is an availability issue; there is no known memory corruption, data disclosure, or remote code execution impact.
### Patches
Upgrade to `[email protected]`.
### Workarounds
Limit the size of the input.
VulDB
SamVerschueren decode-uri-component up to 0.4.x decode resource consumption
vuldb·2026-06-30·CVSS 6.6
CVE-2026-45822 [MEDIUM] SamVerschueren decode-uri-component up to 0.4.x decode resource consumption
A vulnerability was found in SamVerschueren decode-uri-component up to 0.4.x. It has been rated as problematic. Affected by this issue is the function decode. This manipulation causes resource consumption.
This vulnerability is registered as CVE-2026-45822. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
Red Hat
decode-uri-component: decode-uri-component: Denial of Service via crafted input
vendor_redhat·2026-06-30·CVSS 6.6
CVE-2026-45822 [MEDIUM] CWE-1050 decode-uri-component: decode-uri-component: Denial of Service via crafted input
decode-uri-component: decode-uri-component: Denial of Service via crafted input
A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of encoded URI components, consumes excessive CPU resources, which can lead to the application becoming unresponsive and unavailable.
Statement: A denial of service flaw was found in the decode-uri-component npm package. The decode() function exhibits super-linear time complexity when processing input containing many percent-encoded sequences, allowing an attacker to cause significant CPU consumption and event-loop blocking. In Red Hat products where this package is bundled (OpenSh
No detection rules found.
No public exploits indexed.
2026-06-30
Published