Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-38900

37
FAUCET Score

CVE-2022-38900 describes an Improper Input Validation vulnerability in decode-uri-component version 0.2.0, which can lead to a Denial of Service (DoS) condition. This high-severity vulnerability (CVSS 7.5) can be exploited remotely with low attack complexity, requiring no user interaction or privileges. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
0.2.0CPE matchmatch criteria
cpe:2.3:a:decode-uri-component_project:decode-uri-component:0.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
24.93%
Probability of exploitation in next 30 days
EPSS Percentile
97.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.2493 is in the 96th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (37)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['8.2.12', '9.0.6', '9.1.1']
View patch
npmpatch availablevia ghsa
Product: decode-uri-componentFixed in: 0.2.1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: nodejs:14-8040020230306170312.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: nodejs:14-8060020230306170237.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs-0:0.11.6-3.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Migration Toolkit for Containers 1.7Fixed in: rhmtc/openshift-migration-ui-rhel8:v1.7.8-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs14-0:3.6-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs14-nodejs-0:14.21.3-2.el7
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.13-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.13.0-85
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.13.4 asyncFixed in: decode-uri-component
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:14-8070020230306170042.bd1311ed
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-rhel8
redhatno patchvia redhat_api
Product: OpenShift Developer Tools and ServicesFixed in: odo
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: openshift-service-mesh/kiali-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatno patchvia redhat_api
Product: Red Hat A-MQ OnlineFixed in: io.enmasse-enmasse
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: aap-azure-ui
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: io.apicurio-apicurio-registry
redhatno patchvia redhat_api
Product: Red Hat Discovery 1Fixed in: discovery-server-container
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: 389-ds:1.4/389-ds-base
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/ose-console
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console
redhatno patchvia redhat_api
Product: Red Hat Openshift Container Storage 4Fixed in: ocs4/mcg-core-rhel8
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/mcg-core-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: odh-minimal-notebook-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: rhods/odh-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-theia-rhel8-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-agent-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/console-plugin-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-ui-rhel8
redhatno patchvia redhat_api
Product: Migration Toolkit for Applications 6Fixed in: mta/mta-ui-rhel9

Vendor Advisories (3)

bitdefenderllm-bitdefender-2250a01bd7a7224eHIGH

August 2023 Third Party Package Updates in Splunk Enterprise

Aug 30, 2023
npmGHSA-w573-4hg7-7wgqhigh

decode-uri-component vulnerable to Denial of Service (DoS)

Nov 28, 2022
redhatCVE-2022-38900Important

decode-uri-component: improper input validation resulting in DoS

Nov 28, 2022

References

github.com / SamVerschueren/decode-uri-component/issues/5
ExploitIssue TrackingThird Party Advisory
github.com / sindresorhus/query-string/issues/345
ExploitIssue TrackingThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ERN6YE3DS7NBW7UH44SCJBMNC2NWQ7SM
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KAC5KQ2SEWAMQ6UZAUBZ5KXKEOESH375
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QABOUA2I542UTANVZIVFKWMRYVHLV32D
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UW4SCMT3SEUFVIL7YIADQ5K36GJEO6I5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VNV2GNZXOTEDAJRFH3ZYWRUBGIVL7BSU