CVE-2026-93690

Published: Set 18, 2026 Last Modified: Set 22, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,7
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.

835

Loop with Unreachable Exit Condition ('Infinite Loop')

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Amplification
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/garycourt/uri-js/issues/105
https://github.com/garycourt/uri-js
https://github.com/garycourt/uri-js/blob/4.4.0/src/uri.ts#L349
https://github.com/garycourt/uri-js/blob/4.4.0/src/uri.ts#L352-L376
https://github.com/garycourt/uri-js/issues/105
https://www.npmjs.com/package/uri-js/v/4.4.1
https://www.vulncheck.com/advisories/uri-js-through-4.4.1-denial-of-service-via…