---
id: CVE-2026-45822
title: >-
  decode-uri-component: decode-uri-component: Denial of Service via crafted
  input (CVE-2026-45822)
summary: >-
  A flaw was found in the `decode-uri-component` library. This vulnerability
  allows a remote attacker to trigger a Denial of Service (DoS) by submitting
  specially crafted input. The `decode()` function, when processing a large
  number of enco…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-1050
  - CWE-400
  - CWE-405
  - CWE-407
  - CWE-1176
vendor: Red Hat
product: Red Hat Quay 3.12
affected:
  - openshift_pipelines
  - 3scale_api_management_platform 2
  - openshift_distributed_tracing 3
  - migration_toolkit 1.8
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
  - satellite 6.18
  - satellite 6.19
patched:
  - migration_toolkit 1.8
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
  - satellite 6.18
  - satellite 6.19
published: '2026-06-30'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:38:32+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45822.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45822.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-45822'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2494807'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-45822'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45822'
  - url: >-
      https://github.com/SamVerschueren/decode-uri-component/blob/00662938dc7c6241547ae8abce7785cc13ffd3f6/index.js
  - url: >-
      https://github.com/SamVerschueren/decode-uri-component/commit/fa479dafeede7bedf04e5c89aa78f2a78c664005
  - url: 'https://www.npmjs.com/package/decode-uri-component'
  - url: 'https://access.redhat.com/errata/RHSA-2026:41928'
  - url: 'https://access.redhat.com/errata/RHSA-2026:41031'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42146'
  - url: 'https://access.redhat.com/errata/RHSA-2026:43052'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48933'
  - url: 'https://access.redhat.com/errata/RHSA-2026:41066'
  - url: 'https://access.redhat.com/errata/RHSA-2026:40262'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51348'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51197'
  - url: >-
      https://github.com/SamVerschueren/decode-uri-component/security/advisories/GHSA-vcc3-ghjq-m6fr
  - url: 'https://github.com/SamVerschueren/decode-uri-component/releases/tag/v0.5.0'
  - url: 'https://github.com/advisories/GHSA-vcc3-ghjq-m6fr'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00507
epssPercentile: 0.42286
aliases:
  - GHSA-vcc3-ghjq-m6fr
ecosystem: npm
ingestedAt: '2026-08-31T22:14:59.110Z'
---

## Overview

A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of encoded URI components, consumes excessive CPU resources, which can lead to the application becoming unresponsive and unavailable.

## Vendor advisories

- **RHSA-2026:41928** · Red Hat · fixed in: Red Hat Migration Toolkit 1.8 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41928)
- **RHSA-2026:41031** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41031)
- **RHSA-2026:42146** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42146)
- **RHSA-2026:43052** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:43052)
- **RHSA-2026:48933** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48933)
- **RHSA-2026:41066** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41066)
- **RHSA-2026:40262** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:40262)
- **RHSA-2026:51348** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51348)
- **RHSA-2026:51197** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51197)
- **Red Hat VEX** · Important · affected: OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat OpenShift distributed tracing 3 · no fix planned: OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat OpenShift distributed tracing 3 · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45822.json)

**decode-uri-component: decode-uri-component: Denial of Service via crafted input** — rated Important by Red Hat. Released 2026-06-30, updated 2026-09-09.

Affected:

- OpenShift Pipelines
- Red Hat 3scale API Management Platform 2
- Red Hat OpenShift distributed tracing 3

Fixed:

- Red Hat Migration Toolkit 1.8
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- OpenShift Pipelines
- Red Hat 3scale API Management Platform 2
- Red Hat OpenShift distributed tracing 3

Not affected:

- Red Hat Migration Toolkit 1.8
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9
- Red Hat 3scale API Management Platform 2
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:41928
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:41031
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:42146

Workarounds / mitigations:

- Validate and limit the length of any user-controlled input before passing it to decode-uri-component's decode() function. Inputs containing more than approximately 200 percent-encoded tokens (e.g. '%ab' sequences) can trigger noticeable delays. Reject or truncate URI components exceeding a reasonable length threshold before decoding. A fix exists in the upstream repository (commit fa479daf) but has not yet been included in an npm release.

## Package advisory (CVE-2026-45822)

Affected packages:

- `decode-uri-component <= 0.4.2`

Patched in:

- `decode-uri-component 0.5.0`

Source: https://github.com/advisories/GHSA-vcc3-ghjq-m6fr
