uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering. | |
| Title | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars | |
| First Time appeared |
Garycourt
Garycourt uri-js |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:garycourt:uri-js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Garycourt
Garycourt uri-js |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T17:51:36.332Z
Reserved: 2026-09-18T16:30:18.137Z
Link: CVE-2026-93751
No data.
Status : Received
Published: 2026-09-18T18:18:34.177
Modified: 2026-09-18T18:18:34.177
Link: CVE-2026-93751
No data.
OpenCVE Enrichment
No data.
Weaknesses