Decode-Uri-Component Project Decode-Uri-Component vulnerabilities
3 known vulnerabilities affecting decode-uri-component_project/decode-uri-component.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-38900P3HIGHCVSS 7.5v0.2.02022-11-28
CVE-2022-38900 [HIGH] CWE-20 CVE-2022-38900: decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
ghsanvdosv
CVE-2026-45822P3MEDIUM≥ 0, < 0.5.02026-08-31
CVE-2026-45822 [MEDIUM] CWE-1176 decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
### Impact
An attacker who can supply input to `decodeUriComponent()` (directly or via a dependency that uses this package on URL/query/path data) can cause excessive CPU usage and application unresponsiveness. This is an availability issue; there is no known memory
ghsa
CVE-2022-38778P4MEDIUMCVSS 6.5fixed in 0.2.12023-02-08
CVE-2022-38778 [MEDIUM] CWE-20 CVE-2022-38778: A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
nvd