Bug 2538611 (CVE-2026-93690)

Summary: CVE-2026-93690 uri-js: uri-js: Denial of Service via malformed path segments
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, abrianik, abuckta, akhatavk, akostadi, alizardo, amasferr, amctagga, anjoseph, anpicker, anujha, aoconnor, aos-team-art-private, aschwart, asdas, asoldano, aszczucz, ataylor, bbaranow, bbrownin, blitton, bmaxwell, bniver, boliveir, bparees, brasmith, bsmejkal, bstansbe, cdrage, cmyers, cochase, csuconic, dbruscin, dkuc, dlofthou, dmayorov, dnakabaa, doconnor, dpaolell, dranck, drichtar, dschmidt, ehugonne, flucifre, fmariani, ggrzybek, gmalinko, gmeno, gotiwari, gparvin, groman, gtully, hasun, ikhan, istudens, ivassile, iweiss, jachapma, janstey, jbalunas, jchui, jdelft, jfula, jhe, jhorak, jlanda, jlledo, jowilson, jprabhak, jraez, jsherman, jupierce, jwon, kaycoth, kshier, ktsao, kvanderr, lchilton, lcouzens, lgarciaa, lryznaro, mbarnett, mbenjamin, mbiarnes, mcarlett, mhackett, mosmerov, mposolda, mreynolds, msauton, mstipich, msvehla, mvyas, nboldt, nwallace, nyancey, oaljalju, ometelka, orabin, pantinor, parichar, pberan, pdelbell, pesilva, pjindal, pmackay, ppalepu, ppostler, prdhamdh, progier, psrna, ptisnovs, rbobbitt, rexwhite, rgemmell, rgodfrey, rhaigner, rhel-process-autobot, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, snegrini, sostapov, spichugi, ssilvert, stcannon, sthirugn, sthorger, suppawar, syedriko, tasato, tbish, tbordaz, tcunning, thjenkin, tlavocat, tsedmik, tsze, vashirov, vdosoudi, vereddy, vlaad, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in uri-js. A remote attacker can exploit a vulnerability in the `removeDotSegments` function by providing a specially crafted path segment that begins with Unicode line or paragraph separators. This can cause an infinite loop, leading to the Node.js event loop blocking indefinitely and resulting in a denial of service (DoS) for applications using the component.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-22 19:47:35 UTC
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.