← العودة للجدول
CVE-2026-45822
CVE-2026-45822 — decode-uri-component: Denial of service via exponential decoding of malformed pe
📅 2026-09-01
🟡 Medium 🔥 No GHSA Vulnerability Vulnerability

📋 الوصف الكامل

### Impact An attacker who can supply input to `decodeUriComponent()` (directly or via a dependency that uses this package on URL/query/path data) can cause excessive CPU usage and application unresponsiveness. This is an availability issue; there is no known memory corruption, data disclosure, or remote code execution impact. ### Patches Upgrade to `decode-uri-component@0.5.0`. ### Workarounds

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-45822

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v0.5.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←