Impact
The vulnerability exists in uri‑js versions up to 4.4.1, where the removeDotSegments function enters an infinite loop when processing a path segment that begins with a Unicode line or paragraph separator. This results in the Node.js event loop being blocked indefinitely until the process exhausts heap memory. The weakness is identified as CWE‑835: Uncontrolled Resource Consumption, and it directly leads to a denial of service.
Affected Systems
The affected package is garycourt:uri-js, a Node.js library used for URL parsing. Versions through 4.4.1 are vulnerable. Any application that imports uri‑js and calls removeDotSegments, normalize, or resolve with IRI handling enabled may be compromised.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can trigger the exploit by supplying a URL containing a path segment that starts with a Unicode line or paragraph separator. The attack can be carried out remotely if the library processes user‑supplied URLs in a web application, or locally if the library is used in any Node.js process that handles external data. Once triggered, the infinite loop blocks the event loop until heap exhaustion, effectively paralyzing the affected service.
OpenCVE Enrichment