{"id":"CVE-2026-45822","title":"decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)","summary":"A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-1050","CWE-400","CWE-405","CWE-407","CWE-1176"],"vendor":"Red Hat","product":"Red Hat Quay 3.12","affected":["openshift_pipelines","3scale_api_management_platform 2","openshift_distributed_tracing 3","migration_toolkit 1.8","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9","satellite 6.18","satellite 6.19"],"patched":["migration_toolkit 1.8","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9","satellite 6.18","satellite 6.19"],"published":"2026-06-30","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:38:32+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45822.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45822.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-45822"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2494807"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45822"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45822"},{"url":"https://github.com/SamVerschueren/decode-uri-component/blob/00662938dc7c6241547ae8abce7785cc13ffd3f6/index.js"},{"url":"https://github.com/SamVerschueren/decode-uri-component/commit/fa479dafeede7bedf04e5c89aa78f2a78c664005"},{"url":"https://www.npmjs.com/package/decode-uri-component"},{"url":"https://access.redhat.com/errata/RHSA-2026:41928"},{"url":"https://access.redhat.com/errata/RHSA-2026:41031"},{"url":"https://access.redhat.com/errata/RHSA-2026:42146"},{"url":"https://access.redhat.com/errata/RHSA-2026:43052"},{"url":"https://access.redhat.com/errata/RHSA-2026:48933"},{"url":"https://access.redhat.com/errata/RHSA-2026:41066"},{"url":"https://access.redhat.com/errata/RHSA-2026:40262"},{"url":"https://access.redhat.com/errata/RHSA-2026:51348"},{"url":"https://access.redhat.com/errata/RHSA-2026:51197"},{"url":"https://github.com/SamVerschueren/decode-uri-component/security/advisories/GHSA-vcc3-ghjq-m6fr"},{"url":"https://github.com/SamVerschueren/decode-uri-component/releases/tag/v0.5.0"},{"url":"https://github.com/advisories/GHSA-vcc3-ghjq-m6fr"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00507,"epssPercentile":0.42266,"aliases":["GHSA-vcc3-ghjq-m6fr"],"ecosystem":"npm","ingestedAt":"2026-08-31T22:14:59.110Z","slug":"CVE-2026-45822","body":"## Overview\n\nA flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of encoded URI components, consumes excessive CPU resources, which can lead to the application becoming unresponsive and unavailable.\n\n## Vendor advisories\n\n- **RHSA-2026:41928** · Red Hat · fixed in: Red Hat Migration Toolkit 1.8 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41928)\n- **RHSA-2026:41031** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41031)\n- **RHSA-2026:42146** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42146)\n- **RHSA-2026:43052** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:43052)\n- **RHSA-2026:48933** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48933)\n- **RHSA-2026:41066** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41066)\n- **RHSA-2026:40262** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:40262)\n- **RHSA-2026:51348** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51348)\n- **RHSA-2026:51197** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51197)\n- **Red Hat VEX** · Important · affected: OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat OpenShift distributed tracing 3 · no fix planned: OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat OpenShift distributed tracing 3 · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45822.json)\n\n**decode-uri-component: decode-uri-component: Denial of Service via crafted input** — rated Important by Red Hat. Released 2026-06-30, updated 2026-09-09.\n\nAffected:\n\n- OpenShift Pipelines\n- Red Hat 3scale API Management Platform 2\n- Red Hat OpenShift distributed tracing 3\n\nFixed:\n\n- Red Hat Migration Toolkit 1.8\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- OpenShift Pipelines\n- Red Hat 3scale API Management Platform 2\n- Red Hat OpenShift distributed tracing 3\n\nNot affected:\n\n- Red Hat Migration Toolkit 1.8\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n- Red Hat 3scale API Management Platform 2\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:41928\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:41031\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:42146\n\nWorkarounds / mitigations:\n\n- Validate and limit the length of any user-controlled input before passing it to decode-uri-component's decode() function. Inputs containing more than approximately 200 percent-encoded tokens (e.g. '%ab' sequences) can trigger noticeable delays. Reject or truncate URI components exceeding a reasonable length threshold before decoding. A fix exists in the upstream repository (commit fa479daf) but has not yet been included in an npm release.\n\n## Package advisory (CVE-2026-45822)\n\nAffected packages:\n\n- `decode-uri-component <= 0.4.2`\n\nPatched in:\n\n- `decode-uri-component 0.5.0`\n\nSource: https://github.com/advisories/GHSA-vcc3-ghjq-m6fr","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201688,"id":"CVE-2026-45822","ts":1789399606078,"field":"cvss","old":null,"new":"7.5"},{"seq":201687,"id":"CVE-2026-45822","ts":1789399606078,"field":"severity","old":"medium","new":"high"},{"seq":200420,"id":"CVE-2026-45822","ts":1789397216799,"field":"cvss","old":"7.5","new":null},{"seq":200419,"id":"CVE-2026-45822","ts":1789397216799,"field":"severity","old":"high","new":"medium"},{"seq":198344,"id":"CVE-2026-45822","ts":1789391855084,"field":"cvss","old":null,"new":"7.5"},{"seq":198343,"id":"CVE-2026-45822","ts":1789391855084,"field":"severity","old":"medium","new":"high"},{"seq":196137,"id":"CVE-2026-45822","ts":1789383492340,"field":"cvss","old":"7.5","new":null},{"seq":196136,"id":"CVE-2026-45822","ts":1789383492340,"field":"severity","old":"high","new":"medium"},{"seq":195066,"id":"CVE-2026-45822","ts":1789380375261,"field":"cvss","old":null,"new":"7.5"},{"seq":195065,"id":"CVE-2026-45822","ts":1789380375261,"field":"severity","old":"medium","new":"high"},{"seq":193853,"id":"CVE-2026-45822","ts":1789378340202,"field":"cvss","old":"7.5","new":null},{"seq":193852,"id":"CVE-2026-45822","ts":1789378340202,"field":"severity","old":"high","new":"medium"},{"seq":192640,"id":"CVE-2026-45822","ts":1789376325377,"field":"cvss","old":null,"new":"7.5"},{"seq":192639,"id":"CVE-2026-45822","ts":1789376325377,"field":"severity","old":"medium","new":"high"},{"seq":191427,"id":"CVE-2026-45822","ts":1789373248852,"field":"cvss","old":"7.5","new":null},{"seq":191426,"id":"CVE-2026-45822","ts":1789373248852,"field":"severity","old":"high","new":"medium"},{"seq":190212,"id":"CVE-2026-45822","ts":1789369203671,"field":"cvss","old":null,"new":"7.5"},{"seq":190211,"id":"CVE-2026-45822","ts":1789369203671,"field":"severity","old":"medium","new":"high"},{"seq":188999,"id":"CVE-2026-45822","ts":1789368115331,"field":"cvss","old":"7.5","new":null},{"seq":188998,"id":"CVE-2026-45822","ts":1789368115331,"field":"severity","old":"high","new":"medium"},{"seq":187782,"id":"CVE-2026-45822","ts":1789365064779,"field":"cvss","old":null,"new":"7.5"},{"seq":187781,"id":"CVE-2026-45822","ts":1789365064779,"field":"severity","old":"medium","new":"high"},{"seq":186569,"id":"CVE-2026-45822","ts":1789363093623,"field":"cvss","old":"7.5","new":null},{"seq":186568,"id":"CVE-2026-45822","ts":1789363093623,"field":"severity","old":"high","new":"medium"},{"seq":185355,"id":"CVE-2026-45822","ts":1789361027655,"field":"cvss","old":null,"new":"7.5"},{"seq":185354,"id":"CVE-2026-45822","ts":1789361027655,"field":"severity","old":"medium","new":"high"},{"seq":184142,"id":"CVE-2026-45822","ts":1789358016856,"field":"cvss","old":"7.5","new":null},{"seq":184141,"id":"CVE-2026-45822","ts":1789358016856,"field":"severity","old":"high","new":"medium"},{"seq":182393,"id":"CVE-2026-45822","ts":1789354157378,"field":"cvss","old":null,"new":"7.5"},{"seq":182392,"id":"CVE-2026-45822","ts":1789354157378,"field":"severity","old":"medium","new":"high"},{"seq":181186,"id":"CVE-2026-45822","ts":1789352998958,"field":"cvss","old":"7.5","new":null},{"seq":181185,"id":"CVE-2026-45822","ts":1789352998958,"field":"severity","old":"high","new":"medium"},{"seq":179979,"id":"CVE-2026-45822","ts":1789350082638,"field":"cvss","old":null,"new":"7.5"},{"seq":179978,"id":"CVE-2026-45822","ts":1789350082638,"field":"severity","old":"medium","new":"high"},{"seq":178772,"id":"CVE-2026-45822","ts":1789347934015,"field":"cvss","old":"7.5","new":null},{"seq":178771,"id":"CVE-2026-45822","ts":1789347934015,"field":"severity","old":"high","new":"medium"},{"seq":177565,"id":"CVE-2026-45822","ts":1789346220032,"field":"cvss","old":null,"new":"7.5"},{"seq":177564,"id":"CVE-2026-45822","ts":1789346220032,"field":"severity","old":"medium","new":"high"},{"seq":176358,"id":"CVE-2026-45822","ts":1789342851335,"field":"cvss","old":"7.5","new":null},{"seq":176357,"id":"CVE-2026-45822","ts":1789342851335,"field":"severity","old":"high","new":"medium"},{"seq":175812,"id":"CVE-2026-45822","ts":1789338634870,"field":"cvss","old":null,"new":"7.5"},{"seq":175811,"id":"CVE-2026-45822","ts":1789338634870,"field":"severity","old":"medium","new":"high"},{"seq":175682,"id":"CVE-2026-45822","ts":1789338464793,"field":"cvss","old":"7.5","new":null},{"seq":175681,"id":"CVE-2026-45822","ts":1789338464793,"field":"severity","old":"high","new":"medium"},{"seq":174477,"id":"CVE-2026-45822","ts":1789334663101,"field":"cvss","old":null,"new":"7.5"},{"seq":174476,"id":"CVE-2026-45822","ts":1789334663101,"field":"severity","old":"medium","new":"high"},{"seq":173272,"id":"CVE-2026-45822","ts":1789333341799,"field":"cvss","old":"7.5","new":null},{"seq":173271,"id":"CVE-2026-45822","ts":1789333341799,"field":"severity","old":"high","new":"medium"},{"seq":172086,"id":"CVE-2026-45822","ts":1789330943137,"field":"cvss","old":null,"new":"7.5"},{"seq":172085,"id":"CVE-2026-45822","ts":1789330943137,"field":"severity","old":"medium","new":"high"}]}