Home

Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

PUBLISHED Reserved 2025-12-14 | Published 2025-12-14 | Updated 2025-12-14 | Assigner mitre




LOW: 2.9CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-674 Uncontrolled Recursion

Product status

Default status
unknown

Any version
affected

References

github.com/uriparser/uriparser/issues/282

github.com/uriparser/uriparser/pull/284

cve.org (CVE-2025-67899)

nvd.nist.gov (CVE-2025-67899)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.