Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering. | |
| Title | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars | |
| First Time appeared |
Garycourt
Garycourt uri-js |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:garycourt:uri-js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Garycourt
Garycourt uri-js |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T17:51:36.332Z
Reserved: 2026-09-18T16:30:18.137Z
Link: CVE-2026-93751
No data.
Status : Received
Published: 2026-09-18T18:18:34.177
Modified: 2026-09-18T18:18:34.177
Link: CVE-2026-93751
No data.
OpenCVE Enrichment
No data.
