Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Uriparser Project

First CVE: Nov 12, 2018Active for: 8 yearsTotal CVEs: 12
28.9
VTI Score
Low

The Uriparser Project maintains a lightweight URI-parsing library embedded across numerous applications and systems where correct URL handling is critical. Despite a focused product scope, the library's position in the supply chain and its role in parsing untrusted network input make its vulnerabilities broadly consequential. Disclosed vulnerabilities skew strongly toward critical severity and center on a recurring set of memory-safety and control-flow weaknesses—integer overflow, numeric truncation, use-after-free, NULL-pointer dereference, and incorrect control flow—that reflect the low-level parsing demands of URI processing. Defenders should inventory downstream products that depend on this library and treat its updates as high-priority for supply-chain patching; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Uriparser Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2018
7 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-19199CRITICAL
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplicatio
Nov 12, 20189.832NONO
CVE-2018-20721CRITICAL
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 addr
Jan 16, 20199.831NONO
CVE-2018-19198CRITICAL
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is misha
Nov 12, 20189.830NONO
CVE-2026-44928MEDIUM
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
May 8, 20265.326NONO
CVE-2026-44927MEDIUM
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
May 8, 20265.326NONO
CVE-2026-42371MEDIUM
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
Apr 27, 20265.125NONO
CVE-2024-34402HIGH
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
May 3, 20248.625NONO
CVE-2018-19200HIGH
An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.
Nov 12, 20187.525NONO
CVE-2021-46142MEDIUM
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
Jan 6, 20225.521NONO
CVE-2024-34403MEDIUM
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
May 3, 20245.919NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
50%
17%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (33.3%)
Network8 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Uriparser Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Uriparser Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Uriparser Project's Products

View all 1 CNAs →

Top CWEs