#1148402 node-uri-js: CVE-2026-93690

Package:
src:node-uri-js
Source:
src:node-uri-js
Submitter:
Salvatore Bonaccorso
Date:
2026-09-19 14:19:02 UTC
Severity:
normal
Tags:
#1148402#5
Date:
2026-09-19 14:17:32 UTC
From:
To:
Hi,

The following vulnerability was published for node-uri-js.

CVE-2026-93690[0]:
| uri-js through 4.4.1 contains a denial of service vulnerability in
| the removeDotSegments function that loops infinitely when a path
| segment begins with Unicode line or paragraph separators. Attackers
| can trigger this by calling removeDotSegments directly or through
| normalize/resolve functions with IRI handling enabled, causing the
| Node.js event loop to block indefinitely until heap exhaustion.

TTBOMK no upstream fix exists yet at time of writing the bugreport.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93690
https://www.cve.org/CVERecord?id=CVE-2026-93690
[1] https://github.com/garycourt/uri-js/issues/105

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore