
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93690 is a Denial of Service (DoS) vulnerability in the removeDotSegments function of the uri-js npm library (by garycourt), affecting all versions through 4.4.1. When a URI path segment begins with a Unicode LINE SEPARATOR (U+2028) or PARAGRAPH SEPARATOR (U+2029) character, the function enters an infinite loop, blocking the Node.js event loop indefinitely and exhausting heap memory until the process crashes. The vulnerability was disclosed on September 17–18, 2026, via a GitHub issue and subsequently published to the GitHub Advisory Database (GHSA-ffpj-9hx9-929p). It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (Github Advisory, GitHub Issue).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), located in src/uri.ts at lines 349–377. The removeDotSegments function uses the regex RDS5 = /^\/?(?:.|\n)*?(?=\/|$)/ to consume path segments in a while (input.length) loop; however, JavaScript's . metacharacter explicitly excludes Unicode line terminators U+2028 and U+2029. When the input path begins with one of these characters, RDS5 matches an empty string on every iteration, input.slice(0) returns the unchanged input, and the loop never terminates — instead pushing empty strings onto an unbounded output array until V8 raises a fatal out-of-memory error. The vulnerability is reachable via the public API through normalize(input, {iri:true, unicodeSupport:true}), resolve(), or by calling removeDotSegments() directly with attacker-controlled input. No authentication or special privileges are required (GitHub Issue, uri-js source).
Successful exploitation causes complete denial of service for the affected Node.js application instance: the single-threaded event loop is blocked indefinitely, rendering the server unresponsive to all subsequent requests, and heap memory grows unboundedly until V8 terminates the process with a fatal OOM error. Confidentiality and integrity are not affected — the vulnerability is purely an availability impact. Any application that passes user-controlled URI or IRI strings to uri-js's normalize, resolve, or removeDotSegments functions with IRI handling enabled is at risk, which may include a broad range of Node.js web services and API gateways (GitHub Issue, Github Advisory).
A functional proof-of-concept exploit (poc_f6.js) is publicly available on the uri-js GitHub issue tracker, demonstrating the infinite loop and OOM crash with concrete test cases executable via node poc_f6.js <case>. The exploit requires no authentication, no user interaction, and is automatable over the network, making it trivially weaponizable against any exposed Node.js service using the affected library. As of the disclosure date, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.46–0.68%, indicating a currently low but non-negligible probability of exploitation in the near term (Github Advisory, GitHub Issue).
uri-js version ≤ 4.4.1 and passes user-controlled input to normalize(), resolve(), or removeDotSegments() with IRI handling enabled (e.g., {iri:true} or {unicodeSupport:true} options).'http://example.com/a\u2028b' or a direct path string '/a\u2028b'.URI.normalize('http://example.com/a\u2028b', {iri:true, unicodeSupport:true}) or URI.removeDotSegments('/a\u2028b') — this can be via an HTTP request parameter, header, or any other user-supplied input field.removeDotSegments function's RDS5 regex matches an empty string on each iteration because . does not match U+2028/U+2029; input is never shortened, the while (input.length) condition remains true forever, and empty strings are pushed onto the output array each cycle.FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory, crashing the process and taking down the service (GitHub Issue).top, htop, pm2 monit) until process termination.FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory; unexpected Node.js process crash/restart events in process manager logs (PM2, systemd, Docker).%E2%80%A8) or U+2029 (%E2%80%A9) characters in path or query parameters directed at endpoints that perform URI normalization (GitHub Issue).The primary remediation is to update uri-js to a patched version that fixes the infinite loop in removeDotSegments (see GitHub Advisory GHSA-ffpj-9hx9-929p for the patched release once available). If immediate patching is not possible, implement input validation to reject any URI or IRI strings containing U+2028 (LINE SEPARATOR) or U+2029 (PARAGRAPH SEPARATOR) characters before passing them to normalize, resolve, or removeDotSegments. As an additional workaround, disable IRI handling ({iri:false}) if Unicode IRI support is not required by the application, or run URI normalization in a worker thread with a timeout to prevent event loop blocking. The recommended code fix is to change the RDS5 regex from /^\/?(?:.|\n)*?(?=\/|$)/ to /^\/?(?:[\s\S])*?(?=\/|$)/ combined with a loop guard that breaks if input.length does not decrease (Github Advisory, GitHub Issue).
The vulnerability was reported by researcher waydeshio via a detailed GitHub security advisory issue on September 17, 2026, including a complete technical analysis and runnable PoC. Red Hat has acknowledged the issue and opened a Bugzilla tracking entry (bug #2538611). Tenable has added detection coverage via Nessus plugin 348619. No significant public social media discussion or major media coverage has been identified beyond standard CVE aggregator sites (GitHub Issue, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
devel
node-uri-js
focal (esm-apps)
node-uri-js
jammy
node-uri-js
jammy (esm-apps)
node-uri-js
noble
node-uri-js
noble (esm-apps)
node-uri-js
resolute
node-uri-js
resolute (esm-apps)
node-uri-js
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."