Uriparser
Vendor:
First CVE: Nov 12, 2018 · Active for 7 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Uriparser over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2018
7 years ago
Most Recent CVE
May 8, 2026
79 days ago
CVE Severity & Scoring
Uriparser12 CVEs
8%
50%
17%
25%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (33.3%)
Network8 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19199CRITICAL An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplicatio | Nov 12, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-20721CRITICAL URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 addr | Jan 16, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-19198CRITICAL An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is misha | Nov 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2026-44928MEDIUM In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. | May 8, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-44927MEDIUM In uriparser before 1.0.2, there is pointer difference truncation to int in various places. | May 8, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-42371MEDIUM uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. | Apr 27, 2026 | 5.1 | 25 | NO | NO |
CVE-2024-34402HIGH An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow. | May 3, 2024 | 8.6 | 25 | NO | NO |
CVE-2018-19200HIGH An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function. | Nov 12, 2018 | 7.5 | 25 | NO | NO |
CVE-2021-46142MEDIUM An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. | Jan 6, 2022 | 5.5 | 21 | NO | NO |
CVE-2024-34403MEDIUM An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string. | May 3, 2024 | 5.9 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Uriparser
Top CWEs
Versions
No cataloged versions.