uriparser Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with uriparser products.
Products
- uriparser3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Generated title:uriparser EqualsUri Function URI Equality MisclassificationIn uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. CWE-670May 8, 2026 | CVSS2.9v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Generated title:uriparser Pointer Difference Truncation to IntegerIn uriparser before 1.0.2, there is pointer difference truncation to int in various places. CWE-197May 8, 2026 | CVSS2.9v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-42371MEDIUM | Generated title:uriparser Numeric Truncation Vulnerabilityuriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. CWE-197Apr 27, 2026 | CVSS5.1v3.1 | EPSS0.172% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |