uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
History

Wed, 17 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
Title uriparser: uriparser: Unbounded recursion and stack consumption via large input
References
Metrics threat_severity

None

threat_severity

Low


Mon, 15 Dec 2025 23:30:00 +0000

Type Values Removed Values Added
References

Mon, 15 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 22:30:00 +0000

Type Values Removed Values Added
Description uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.
First Time appeared Uriparser Project
Uriparser Project uriparser
Weaknesses CWE-674
CPEs cpe:2.3:a:uriparser_project:uriparser:*:*:*:*:*:*:*:*
Vendors & Products Uriparser Project
Uriparser Project uriparser
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-14T22:17:42.217Z

Updated: 2025-12-15T23:04:11.694Z

Reserved: 2025-12-14T22:17:41.925Z

Link: CVE-2025-67899

cve-icon Vulnrichment

Updated: 2025-12-15T23:04:11.694Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-14T23:15:37.033

Modified: 2025-12-15T23:15:57.293

Link: CVE-2025-67899

cve-icon Redhat

Severity : Low

Publid Date: 2025-12-14T22:17:42Z

Links: CVE-2025-67899 - Bugzilla