CVE-2026-45822General

LOWCVSS 6.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-30); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-30: 1Mentions · 2026-09-11: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-06-30: 1Technical Details · 2026-09-11: 106-3009-11
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-301
General1
2026-09-111
Patch1
Full discourse2 posts
  • Akshara Hegde - oss/acc@akshara_dev
    Patch

    django-jet-3-calm 5.5.2 is out 🔒 security patch: browserslist → 4.28.9 (CVE-2026-73088) and decode-uri-component pinned to 0.5.0 (ReDoS, CVE-2026-45822) drop-in upgrade, no breaking changes

    Post summary

    The release of django-jet-3-calm 5.5.2 includes security patches for CVE-2026-73088 by upgrading browserslist to 4.28.9, and for CVE-2026-45822 (ReDoS) by pinning decode‑uri‑component to 0.5.0, offering a drop‑in upgrade without breaking changes.

    10020461
    644 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45822 Denial of Service Vulnerability in decode-uri-component Through 0.4.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45822

    Post summary

    A newly announced Denial of Service vulnerability (CVE‑2026‑45822) in decode‑uri‑component through version 0.4.1 is referenced, but no PoC, exploit, or patch information is provided.

    0000091
    4.1K followersView on X

Explore more