Skip to main content

Improper Handling of Unicode Encoding in uri-js

CVE-2026-93751

  • uri-js
Severity Medium
Score 6.9/10

Summary

uri-js contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-176 - Improper Handling of Unicode Encoding

The software does not properly handle when an input contains Unicode encoding.

Advisory Timeline

  • Published