Description
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering. | |
| Title | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars | |
| First Time appeared |
Garycourt
Garycourt uri-js |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:garycourt:uri-js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Garycourt
Garycourt uri-js |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T17:51:36.332Z
Reserved: 2026-09-18T16:30:18.137Z
Link: CVE-2026-93751
No data.
Status : Received
Published: 2026-09-18T18:18:34.177
Modified: 2026-09-18T18:18:34.177
Link: CVE-2026-93751
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-176
Improper Handling of Unicode Encoding