Home/Product/uriparser project uriparser
Product

uriparser project uriparser

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44928
< 1.0.2
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
2.9LOW
CVE-2026-44927
< 1.0.2
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
2.9LOW
CVE-2026-42371
< 1.0.1
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
5.1MEDIUM
CVE-2024-34403
<= 0.9.7
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string
5.9MEDIUM
CVE-2024-34402
<= 0.9.7
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or valu
8.6HIGH
CVE-2021-46142
< 0.9.6
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
5.5MEDIUM
CVE-2021-46141
< 0.9.6
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
5.5MEDIUM
CVE-2018-20721
< 0.9.1
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParseEx functions) for an incomplete URI wit
9.8CRITICAL
CVE-2018-19200
< 0.9.0
An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* functi
7.5HIGH
CVE-2018-19199
< 0.9.0
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQuery
9.8CRITICAL
CVE-2018-19198
< 0.9.0
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQu
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin