CVE-2026-45822High· 7.5▾ TwilightA flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
Last analysed / modified upstream
7.5 → —
high → medium
— → 7.5
medium → high
7.5 → —
high → medium
— → 7.5
medium → high
7.5 → —
high → medium
— → 7.5
medium → high
A flaw was found in the decode-uri-component library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The decode() function, when processing a large number of encoded URI components, consumes excessive CPU resources, which can lead to the application becoming unresponsive and unavailable.
decode-uri-component: decode-uri-component: Denial of Service via crafted input — rated Important by Red Hat. Released 2026-06-30, updated 2026-09-09.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:41928 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:41031 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:42146
Workarounds / mitigations:
Affected packages:
decode-uri-component <= 0.4.2Patched in:
decode-uri-component 0.5.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
CVE-2026-71491High· 7.5sqlparse is a non-validating SQL parser module for Python
CVE-2026-10143High· 7.5kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count (CVE-2026-10143)
CVE-2026-54060High· 7.5python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)
CVE-2026-50193High· 7.5jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)
CVE-2026-48779High· 7.5ws is an open source WebSocket client and server for Node.js