Improper Handling of Unicode Encoding in uri-js
CVE-2026-93751
- uri-js
Summary
uri-js contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-176 - Improper Handling of Unicode Encoding
The software does not properly handle when an input contains Unicode encoding.
Advisory Timeline
- Published