CVE-2026-44927: uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Published May 8, 2026
·Updated
Fixed CVE-2026-44927 (In uriparser before 1.0.2, there is pointer difference truncation to int in various places). (CVE-2026-44927)
Affected Software
3 affected componentsFixes available
uriparser uriparser<1.0.2
Uriparser Project Uriparser<1.0.2
PHP PHP<8.5.7
8.5.7
Remediation
Patch Available
Event History
May 8, 2026
CVE Published
via MITRE·07:13 AM
Data Sourced
via MITRE·07:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 4, 2026
Data Sourced
via PHP·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44927?
CVE-2026-44927 has been categorized as a medium severity vulnerability.
2
How do I fix CVE-2026-44927?
To fix CVE-2026-44927, upgrade uriparser to version 1.0.2 or higher.
3
What are the implications of CVE-2026-44927?
The implications of CVE-2026-44927 include potential data corruption or crashes due to pointer difference truncation.
4
Which versions of uriparser are affected by CVE-2026-44927?
Versions of uriparser prior to 1.0.2 are affected by CVE-2026-44927.
5
Is CVE-2026-44927 a remote or local vulnerability?
CVE-2026-44927 is considered a local vulnerability, as it affects operations within the software itself.