https://seclists.org/oss-sec/2026/q2/505: uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Published May 12, 2026
·Updated
Affected Software
1 affected component
uriparser uriparser<1.0.2
Frequently Asked Questions
1
What is the severity of CVE-2026-44927?
CVE-2026-44927 is considered a low-severity security issue.
2
How do I fix CVE-2026-44927?
To fix CVE-2026-44927, upgrade uriparser to version 1.0.2 or later.
3
What does CVE-2026-44927 involve?
CVE-2026-44927 involves pointer difference truncation to int in various places within uriparser.
4
Is CVE-2026-44927 easy to exploit?
CVE-2026-44927 is considered hard to exploit in reality due to the requirement of a 2gb+ input.
5
Which version of uriparser addresses CVE-2026-44927?
Version 1.0.2 of uriparser addresses CVE-2026-44927.