CVE-2026-42371Disclosure(uriparser_project / uriparser)

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch uriparser_project uriparser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-197

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • uriparser

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
uriparser

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-27: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-28: 104-2704-28
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-272
Disclosure1General1
2026-04-281
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    uriparser 1.0.1 fixes CVE-2026-42371 (integer overflow) https://www.openwall.com/lists/oss-security/2026/04/27/2

    Post summary

    uriparser 1.0.1 release includes a fix for CVE-2026-42371 (integer overflow); no exploit, PoC, or active exploitation information is provided.

    00031301
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42371 uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. https://www.cve.org/CVERecord?id=CVE-2026-42371

    Post summary

    CVE-2026-42371 highlights a numeric truncation issue in uriparser prior to 1.0.1 that can be triggered with URIs of gigabyte‑sized length. The post cites the CVE record but offers no exploit, patch, or PoC.

    0000080
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42371 Numeric Truncation Vulnerability in uriparser Before 1.0.1 Text R... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42371 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post briefly notes the existence of CVE-2026-42371 with the vulnerability type and affected library, providing links to further details but lacking any exploit, patch, or active exploitation information.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuriparser_projecturiparser---

Explore more