CVE-2026-93751: uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars

Published Sep 18, 2026
·
Updated

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.

Affected Software

1 affected component
npm/uri-js<=4.4.1

Event History

Sep 18, 2026
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using npm/uri-js through version 4.4.1 are affected when they decode untrusted percent-encoded URI data and pass the result to downstream consumers that do not filter the resulting metacharacters.

2

What does an attacker need to exploit this issue?

An attacker needs to supply a crafted percent-encoded payload. The reported vector is network-accessible and requires neither authentication nor user interaction.

3

What can successful exploitation enable?

Invalid or overlong percent-encoded sequences can be decoded into ASCII metacharacters, potentially bypassing platform decoder validation. Downstream processing may then allow path-traversal or CRLF injection sequences, with low reported confidentiality and integrity impact.

4

How can I determine whether my application is affected?

Check whether it includes uri-js version 4.4.1 or earlier. Prioritize applications that use uri-js to decode externally supplied URI components before using them in paths, headers, or other downstream processing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203