Description
A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

An unhandled exception is triggered in the uri‑js library when the URI.parse function processes a malformed mailto link. The flaw lies in src/schemes/mailto.ts and is classified as Unhandled Exception (CWE‑248). When invoked with crafted input the library throws an uncaught exception, causing the host application to crash. The flaw can be triggered remotely as exploit code is publicly available.

Affected Systems

The vulnerability affects all installations of the garycourt uri‑js package up to and including version 4.4.1. It is part of the Mailto Header Handler module that parses mailto schemes. JavaScript, Node.js, and any downstream projects that depend on uri‑js without updating to a newer release are exposed. The vendor is the original author, Gary Courtney.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. EPSS is not provided and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted mailto links to components that load uri‑js over a network‑accessible interface. When the library processes the malformed input it throws an uncaught exception, causing the host application to crash and leading to a denial of service. The description does not specify any requirement for authentication or privileged access.

Generated by OpenCVE AI on September 30, 2026 at 23:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the garycourt uri‑js package to a version newer than 4.4.1 once a patched release is available.
  • Perform input validation or sanitization of mailto URIs before passing them to URI.parse to prevent malformed data from reaching the library.
  • Monitor application logs for unhandled exception errors or crashes related to mailto parsing and implement fallback handling to avoid downtime.

Generated by OpenCVE AI on September 30, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title garycourt uri-js Mailto Header mailto.ts URI.parse uncaught exception
First Time appeared Garycourt
Garycourt uri-js
Weaknesses CWE-248
CPEs cpe:2.3:a:garycourt:uri-js:*:*:*:*:*:*:*:*
Vendors & Products Garycourt
Garycourt uri-js
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Garycourt Uri-js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T19:55:03.125Z

Reserved: 2026-09-30T14:07:47.711Z

Link: CVE-2026-103387

cve-icon Vulnrichment

Updated: 2026-09-30T19:54:58.745Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T20:17:30.620

Modified: 2026-10-01T02:12:10.020

Link: CVE-2026-103387

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-30T19:45:07Z

Links: CVE-2026-103387 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:30:07Z

Weaknesses