Uri.js is a JavaScript URI parsing and manipulation library with a narrow product scope but significant presence in the web application supply chain, where a flaw can propagate across dependent projects. Its vulnerability profile centers on input-validation weaknesses including improper URL parsing, open redirects, and authorization-bypass conditions that are inherent to URI-handling logic. Defenders should audit downstream applications that bundle this library and prioritize updates when available; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uri.Js Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27516HIGH URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. | Feb 22, 2021 | 7.5 | 25 | NO | NO |
CVE-2022-0613MEDIUM Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. | Feb 16, 2022 | 6.5 | 24 | NO | NO |
CVE-2022-0868MEDIUM Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. | Mar 6, 2022 | 6.1 | 23 | NO | NO |
CVE-2021-3647MEDIUM URI.js is vulnerable to URL Redirection to Untrusted Site | Jul 16, 2021 | 6.1 | 22 | NO | NO |
CVE-2020-26291MEDIUM URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at | Dec 31, 2020 | 6.5 | 22 | NO | NO |
CVE-2022-1243MEDIUM CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11. | Apr 5, 2022 | 6.1 | 20 | NO | NO |
CVE-2022-1233MEDIUM URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. | Apr 4, 2022 | 6.1 | 17 | NO | NO |
CVE-2022-24723MEDIUM URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This | Mar 3, 2022 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uri.Js Project.
Media articles that mention a CVE ID that affects a product developed by Uri.Js Project — matched by CVE ID, not by vendor name.