CVE-2026-42371

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:uriparser_project:uriparser:*:*:*:*:*:*:*:*

History

18 May 2026, 17:58

Type Values Removed Values Added
CPE cpe:2.3:a:uriparser_project:uriparser:*:*:*:*:*:*:*:*
First Time Uriparser Project uriparser
Uriparser Project
References () https://github.com/uriparser/uriparser/pull/298 - () https://github.com/uriparser/uriparser/pull/298 - Issue Tracking, Patch
References () https://uriparser.github.io - () https://uriparser.github.io - Product
References () http://www.openwall.com/lists/oss-security/2026/04/27/2 - () http://www.openwall.com/lists/oss-security/2026/04/27/2 - Mailing List, Third Party Advisory

27 Apr 2026, 15:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/04/27/2 -

27 Apr 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-27 07:16

Updated : 2026-05-18 17:58


NVD link : CVE-2026-42371

Mitre link : CVE-2026-42371

CVE.ORG link : CVE-2026-42371


JSON object : View

Products Affected

uriparser_project

  • uriparser
CWE
CWE-197

Numeric Truncation Error