Description
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

The vulnerability exists in uri‑js versions up to 4.4.1, where the removeDotSegments function enters an infinite loop when processing a path segment that begins with a Unicode line or paragraph separator. This results in the Node.js event loop being blocked indefinitely until the process exhausts heap memory. The weakness is identified as CWE‑835: Uncontrolled Resource Consumption, and it directly leads to a denial of service.

Affected Systems

The affected package is garycourt:uri-js, a Node.js library used for URL parsing. Versions through 4.4.1 are vulnerable. Any application that imports uri‑js and calls removeDotSegments, normalize, or resolve with IRI handling enabled may be compromised.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can trigger the exploit by supplying a URL containing a path segment that starts with a Unicode line or paragraph separator. The attack can be carried out remotely if the library processes user‑supplied URLs in a web application, or locally if the library is used in any Node.js process that handles external data. Once triggered, the infinite loop blocks the event loop until heap exhaustion, effectively paralyzing the affected service.

Generated by OpenCVE AI on September 19, 2026 at 18:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade uri‑js to a version newer than 4.4.1 that contains the patch for the infinite loop bug.
  • If an upgrade is not possible, disable IRI handling in calls to removeDotSegments, normalize, or resolve when processing untrusted input.
  • Validate or sanitize input to remove Unicode line or paragraph separators before passing strings to uri‑js functions.

Generated by OpenCVE AI on September 19, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.
Title uri-js through 4.4.1 Denial of Service via removeDotSegments
First Time appeared Garycourt
Garycourt uri-js
Weaknesses CWE-835
CPEs cpe:2.3:a:garycourt:uri-js:*:*:*:*:*:node.js:*:*
Vendors & Products Garycourt
Garycourt uri-js
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Garycourt Uri-js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:06.313Z

Reserved: 2026-09-18T14:39:02.165Z

Link: CVE-2026-93690

cve-icon Vulnrichment

Updated: 2026-09-18T19:13:47.380Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:16.000

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93690

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T15:06:04Z

Links: CVE-2026-93690 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')