GHSA-vcc3-ghjq-m6fr: Npm/decode-uri-component vulnerability

Published Aug 31, 2026
·
Updated

Impact An attacker who can supply input to decodeUriComponent() (directly or via a dependency that uses this package on URL/query/path data) can cause excessive CPU usage and application unresponsiveness. This is an availability issue; there is no known memory corruption, data disclosure, or remote code execution impact.

Patches Upgrade to decode-uri-component@0.5.0.

Workarounds Limit the size of the input.

Affected Software

1 affected componentFixes available
npm/decode-uri-component<=0.4.2
0.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/decode-uri-component to a version that resolves this vulnerability.

    Fixed in 0.5.0
  2. Upgrade

    Upgrade decode-uri-component to a version that resolves this vulnerability.

    Fixed in 0.5.0
  3. Compensating control

    Limit the size of the input supplied to decodeUriComponent() (directly or via dependencies) to prevent excessive CPU usage and application unresponsiveness.

Event History

Aug 31, 2026
Advisory Published
via GitHub·10:10 PM
Data Sourced
via GitHub·10:10 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications are exposed if an attacker can supply data that reaches decodeUriComponent(), either directly or through a dependency that applies it to URL, query-string, or path data.

2

What is required to exploit the issue?

An attacker needs control over input processed by decodeUriComponent(). Successful exploitation causes excessive CPU use and can make the application unresponsive.

3

What can be done if upgrading is not immediately possible?

Limit the size of input before it reaches decodeUriComponent(). This reduces the opportunity for oversized attacker-controlled values to trigger excessive CPU usage.

4

What version contains the fix?

Upgrade decode-uri-component to version 0.5.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203