PatchSiren

uriparser CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM uriparser CVE published 2026-04-27

CVE-2026-42371

CVE-2026-42371 is a numeric truncation vulnerability in uriparser before version 1.0.1. The flaw occurs in text range comparison logic when processing URIs with lengths measured in gigabytes. An attacker could potentially trigger a denial of service condition by supplying an exceptionally large URI that causes incorrect range calculations due to integer truncation. The vulnerability requires local access [truncated]