High severity7.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93690
CVE-2026-93690
Description
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.