Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42371

Опубликовано: 27 апр. 2026
Источник: redhat
CVSS3: 4.7

Описание

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

A flaw was found in uriparser. This vulnerability occurs due to numeric truncation in text range comparison when an application processes extremely long Uniform Resource Identifiers (URIs), specifically those with lengths in gigabytes. A local attacker could exploit this flaw by providing a malformed, excessively long URI, leading to a Denial of Service (DoS) condition where the application becomes unavailable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7uriparserFix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3uriparserFix deferred
Red Hat Hardened Imagesuriparser-main-1.0.1-1.hum1FixedRHSA-2026:1243030.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2463159uriparser: uriparser: Denial of Service via numeric truncation with oversized URIs

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
4 месяца назад

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

CVSS3: 5.1
nvd
4 месяца назад

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

CVSS3: 5.1
debian
4 месяца назад

uriparser before 1.0.1 has numeric truncation in text range comparison ...

CVSS3: 5.1
github
4 месяца назад

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

4.7 Medium

CVSS3