Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67899

Опубликовано: 14 дек. 2025
Источник: redhat
CVSS3: 2.9

Описание

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

A flaw was found in uriparser. This vulnerability allows unbounded recursion and stack consumption via large input containing many commas.

Отчет

This vulnerability is rated Low for Red Hat because it requires local access and a specially crafted URI to trigger unbounded recursion, leading to stack consumption. The attack complexity is high, limiting its practical impact in most Red Hat deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7uriparserOut of support scope
Red Hat Enterprise Linux AI (RHEL AI) 3uriparserFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2422120uriparser: uriparser: Unbounded recursion and stack consumption via large input

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
4 месяца назад

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

CVSS3: 2.9
nvd
4 месяца назад

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

CVSS3: 2.9
debian
4 месяца назад

uriparser through 0.9.9 allows unbounded recursion and stack consumpti ...

suse-cvrf
около 2 месяцев назад

Security update for uriparser

CVSS3: 2.9
github
4 месяца назад

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

2.9 Low

CVSS3