cbcvebase.
CVE-2026-45822
published 2026-06-30

CVE-2026-45822: decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls…

PriorityP338medium6.6CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSNAUYRUVDREMUAmber
EPSS
0.51%
42.3th percentile
decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.

Affected

18 ranges
VendorProductVersion rangeFixed in
3scale-amp2system-rhel7——
3scale-amp2system-rhel8——
3scale-amp2system-rhel9——
3scale-amp21system——
3scale-amp22system——
decode-uri-component_projectdecode-uri-component——
decode-uri-component_projectdecode-uri-component>= 0 < 0.5.00.5.0
openshift-pipelinespipelines-console-plugin-pf5-rhel9——
openshift-pipelinespipelines-console-plugin-rhel9——
openshift4ose-console——
openshift4ose-console-rhel9——
quayquay-rhel8——
quayquay-rhel9——
rhmtcopenshift-migration-ui-rhel8——
rhoaiodh-mlflow-rhel9——
rhosdttempo-jaeger-query-rhel9——
samverschuerendecode-uri-component>= 0.1.0 < 0.5.00.5.0
satelliteiop-vulnerability-frontend-rhel9——

CVSS provenance

nvdv4.06.6MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.