{"id":"CVE-2026-93690","published":"2026-09-18T16:17:16.000","lastModified":"2026-09-22T20:25:55.870","description":"uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-835"],"vendors":[],"products":[],"references":[{"url":"https://github.com/garycourt/uri-js","tags":[]},{"url":"https://github.com/garycourt/uri-js/blob/4.4.0/src/uri.ts#L349","tags":[]},{"url":"https://github.com/garycourt/uri-js/blob/4.4.0/src/uri.ts#L352-L376","tags":[]},{"url":"https://github.com/garycourt/uri-js/issues/105","tags":[]},{"url":"https://www.npmjs.com/package/uri-js/v/4.4.1","tags":[]},{"url":"https://www.vulncheck.com/advisories/uri-js-through-4.4.1-denial-of-service-via-removedotsegments","tags":[]},{"url":"https://github.com/garycourt/uri-js/issues/105","tags":[]}],"exploitRefs":[{"url":"https://github.com/garycourt/uri-js","tags":[]},{"url":"https://github.com/garycourt/uri-js/blob/4.4.0/src/uri.ts#L349","tags":[]},{"url":"https://github.com/garycourt/uri-js/blob/4.4.0/src/uri.ts#L352-L376","tags":[]},{"url":"https://github.com/garycourt/uri-js/issues/105","tags":[]},{"url":"https://github.com/garycourt/uri-js/issues/105","tags":[]}],"hasPoc":true,"ai":null}