The Decode Uri Component Project maintains a focused, narrow-scope utility library for URI component decoding that is embedded across a range of web and JavaScript-based applications. The observed vulnerability surface reflects the parsing and handling demands of URI decoding logic; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Decode Uri Component Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38900HIGH decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. | Nov 28, 2022 | 7.5 | 37 | NO | NO |
CVE-2022-38778MEDIUM A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server proce | Feb 8, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Decode Uri Component Project.
Media articles that mention a CVE ID that affects a product developed by Decode Uri Component Project — matched by CVE ID, not by vendor name.