cbcvebase.

Uriparser Project Uriparser vulnerabilities

12 known vulnerabilities affecting uriparser_project/uriparser.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2MEDIUM6LOW1

Vulnerabilities

Page 1 of 1
CVE-2024-34402P3HIGHCVSS 8.6≤ 0.9.72024-05-03
CVE-2024-34402 [HIGH] CWE-190 CVE-2024-34402: An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
nvdosv
CVE-2018-19198P3CRITICALCVSS 9.8fixed in 0.9.02018-11-12
CVE-2018-19198 [CRITICAL] CWE-787 CVE-2018-19198: An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a ur An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
nvdosv
CVE-2018-19199P3CRITICALCVSS 9.8fixed in 0.9.02018-11-12
CVE-2018-19199 [CRITICAL] CWE-190 CVE-2018-19199: An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriCo An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
nvdosv
CVE-2018-20721P3CRITICALCVSS 9.8fixed in 0.9.12019-01-16
CVE-2018-20721 [CRITICAL] CWE-125 CVE-2018-20721: URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functi URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.
nvdosv
CVE-2018-19200P3HIGHCVSS 7.5fixed in 0.9.02018-11-12
CVE-2018-19200 [HIGH] CWE-476 CVE-2018-19200: An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL i An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.
nvdosv
CVE-2024-34403P4MEDIUMCVSS 5.9≤ 0.9.72024-05-03
CVE-2024-34403 [MEDIUM] CWE-190 CVE-2024-34403: An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an inte An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
nvdosv
CVE-2026-44928P4MEDIUMCVSS 5.3fixed in 1.0.22026-05-08
CVE-2026-44928 [MEDIUM] CWE-670 CVE-2026-44928: In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
nvd
CVE-2026-44927P4MEDIUMCVSS 5.3fixed in 1.0.22026-05-08
CVE-2026-44927 [MEDIUM] CWE-197 CVE-2026-44927: In uriparser before 1.0.2, there is pointer difference truncation to int in various places. In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
nvd
CVE-2021-46141P4MEDIUMCVSS 5.5fixed in 0.9.62022-01-06
CVE-2021-46141 [MEDIUM] CWE-416 CVE-2021-46141: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUri An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
nvdosv
CVE-2021-46142P4MEDIUMCVSS 5.5fixed in 0.9.62022-01-06
CVE-2021-46142 [MEDIUM] CWE-416 CVE-2021-46142: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormali An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
nvdosv
CVE-2026-42371P4MEDIUMCVSS 5.1fixed in 1.0.12026-04-27
CVE-2026-42371 [MEDIUM] CWE-197 CVE-2026-42371: uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts UR uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
nvd
CVE-2025-67899P4LOWCVSS 2.9≤ 0.9.92025-12-14
CVE-2025-67899 [LOW] CWE-674 CVE-2025-67899: uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMu uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
nvd