An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow. https://github.com/uriparser/uriparser/issues/183 https://github.com/uriparser/uriparser/pull/185 https://github.com/uriparser/uriparser/commit/760ade2947415dbb100053cf793c2f96fe257386
Created uriparser tracking bugs for this issue: Affects: epel-8 [bug 2278810] Affects: fedora-38 [bug 2278811] Affects: fedora-39 [bug 2278812] Affects: fedora-40 [bug 2278813]