Hi,
The following vulnerability was published for node-uri-js.
CVE-2026-93751[0]:
| uri-js through 4.4.1 contains an improper UTF-8 decoding
| vulnerability in pctDecChars() that decodes invalid and overlong
| percent-encoded sequences into ASCII metacharacters. Attackers can
| craft percent-encoded payloads to bypass platform decoder validation
| and inject path traversal or CRLF sequences that downstream
| consumers process without filtering.
TTBOMK, no upstream fix yet exists at time of writing the bugreport.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-93751
https://www.cve.org/CVERecord?id=CVE-2026-93751
[1] https://github.com/garycourt/uri-js/issues/106
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore