https://seclists.org/oss-sec/2026/q2/506: uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Published May 12, 2026
·Updated
Affected Software
1 affected component
uriparser uriparser<1.0.2
Frequently Asked Questions
1
What is the severity of CVE-2026-44927?
CVE-2026-44927 is classified as low severity due to the specific payload size required for exploitation.
2
How do I fix CVE-2026-44927?
To fix CVE-2026-44927, upgrade uriparser to version 1.0.2 or later.
3
What type of vulnerability is CVE-2026-44927?
CVE-2026-44927 involves pointer difference truncation to int, which can lead to issues under specific conditions.
4
Can CVE-2026-44927 be exploited remotely?
Yes, CVE-2026-44927 has a remote vector for exploitation, although it requires specific conditions.
5
What software is affected by CVE-2026-44927?
The vulnerability affects uriparser versions prior to 1.0.2.