CVE-2026-93690: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-93690 is a Denial of Service (DoS) vulnerability in the removeDotSegments function of the uri-js npm library (by garycourt), affecting all versions through 4.4.1. When a URI path segment begins with a Unicode LINE SEPARATOR (U+2028) or PARAGRAPH SEPARATOR (U+2029) character, the function enters an infinite loop, blocking the Node.js event loop indefinitely and exhausting heap memory until the process crashes. The vulnerability was disclosed on September 17–18, 2026, via a GitHub issue and subsequently published to the GitHub Advisory Database (GHSA-ffpj-9hx9-929p). It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (Github Advisory, GitHub Issue).

Technical details

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), located in src/uri.ts at lines 349–377. The removeDotSegments function uses the regex RDS5 = /^\/?(?:.|\n)*?(?=\/|$)/ to consume path segments in a while (input.length) loop; however, JavaScript's . metacharacter explicitly excludes Unicode line terminators U+2028 and U+2029. When the input path begins with one of these characters, RDS5 matches an empty string on every iteration, input.slice(0) returns the unchanged input, and the loop never terminates — instead pushing empty strings onto an unbounded output array until V8 raises a fatal out-of-memory error. The vulnerability is reachable via the public API through normalize(input, {iri:true, unicodeSupport:true}), resolve(), or by calling removeDotSegments() directly with attacker-controlled input. No authentication or special privileges are required (GitHub Issue, uri-js source).

Impact

Successful exploitation causes complete denial of service for the affected Node.js application instance: the single-threaded event loop is blocked indefinitely, rendering the server unresponsive to all subsequent requests, and heap memory grows unboundedly until V8 terminates the process with a fatal OOM error. Confidentiality and integrity are not affected — the vulnerability is purely an availability impact. Any application that passes user-controlled URI or IRI strings to uri-js's normalize, resolve, or removeDotSegments functions with IRI handling enabled is at risk, which may include a broad range of Node.js web services and API gateways (GitHub Issue, Github Advisory).

Exploitability

A functional proof-of-concept exploit (poc_f6.js) is publicly available on the uri-js GitHub issue tracker, demonstrating the infinite loop and OOM crash with concrete test cases executable via node poc_f6.js <case>. The exploit requires no authentication, no user interaction, and is automatable over the network, making it trivially weaponizable against any exposed Node.js service using the affected library. As of the disclosure date, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.46–0.68%, indicating a currently low but non-negligible probability of exploitation in the near term (Github Advisory, GitHub Issue).

Exploitation steps

  1. Identify target: Locate a Node.js application that uses uri-js version ≤ 4.4.1 and passes user-controlled input to normalize(), resolve(), or removeDotSegments() with IRI handling enabled (e.g., {iri:true} or {unicodeSupport:true} options).
  2. Craft malicious payload: Construct a URI string containing a Unicode LINE SEPARATOR (U+2028) or PARAGRAPH SEPARATOR (U+2029) in the path segment, e.g., 'http://example.com/a\u2028b' or a direct path string '/a\u2028b'.
  3. Deliver payload: Submit the crafted URI to any application endpoint that internally calls URI.normalize('http://example.com/a\u2028b', {iri:true, unicodeSupport:true}) or URI.removeDotSegments('/a\u2028b') — this can be via an HTTP request parameter, header, or any other user-supplied input field.
  4. Trigger infinite loop: The removeDotSegments function's RDS5 regex matches an empty string on each iteration because . does not match U+2028/U+2029; input is never shortened, the while (input.length) condition remains true forever, and empty strings are pushed onto the output array each cycle.
  5. Achieve DoS: The Node.js event loop blocks indefinitely; heap memory grows until V8 emits FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory, crashing the process and taking down the service (GitHub Issue).

Indicators of compromise

  • Process Behavior: Node.js process consuming 100% CPU with no forward progress; steadily increasing heap memory usage visible via process monitors (e.g., top, htop, pm2 monit) until process termination.
  • Logs: V8 fatal error message in application logs or stderr: FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory; unexpected Node.js process crash/restart events in process manager logs (PM2, systemd, Docker).
  • Application Logs: Requests that never receive a response (hanging connections); upstream timeout errors from load balancers or reverse proxies (e.g., Nginx 504 Gateway Timeout) coinciding with process crash.
  • Network: Inbound HTTP requests containing URL-encoded or raw U+2028 (%E2%80%A8) or U+2029 (%E2%80%A9) characters in path or query parameters directed at endpoints that perform URI normalization (GitHub Issue).

Mitigation and workarounds

The primary remediation is to update uri-js to a patched version that fixes the infinite loop in removeDotSegments (see GitHub Advisory GHSA-ffpj-9hx9-929p for the patched release once available). If immediate patching is not possible, implement input validation to reject any URI or IRI strings containing U+2028 (LINE SEPARATOR) or U+2029 (PARAGRAPH SEPARATOR) characters before passing them to normalize, resolve, or removeDotSegments. As an additional workaround, disable IRI handling ({iri:false}) if Unicode IRI support is not required by the application, or run URI normalization in a worker thread with a timeout to prevent event loop blocking. The recommended code fix is to change the RDS5 regex from /^\/?(?:.|\n)*?(?=\/|$)/ to /^\/?(?:[\s\S])*?(?=\/|$)/ combined with a loop guard that breaks if input.length does not decrease (Github Advisory, GitHub Issue).

Community reactions

The vulnerability was reported by researcher waydeshio via a detailed GitHub security advisory issue on September 17, 2026, including a complete technical analysis and runnable PoC. Red Hat has acknowledged the issue and opened a Bugzilla tracking entry (bug #2538611). Tenable has added detection coverage via Nessus plugin 348619. No significant public social media discussion or major media coverage has been identified beyond standard CVE aggregator sites (GitHub Issue, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

node-uri-js

Affected

sid

node-uri-js

Affected

trixie

node-uri-js

Affected

Ubuntu

Unknown

devel

node-uri-js

Unknown

focal (esm-apps)

node-uri-js

Unknown

jammy

node-uri-js

Unknown

jammy (esm-apps)

node-uri-js

Unknown

noble

node-uri-js

Unknown

noble (esm-apps)

node-uri-js

Unknown

resolute

node-uri-js

Unknown

resolute (esm-apps)

node-uri-js

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/ose-console

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-102276HIGH7.5
  • JavaScript logoJavaScript
  • sgx-enclave-latest-tdqe-unsigned
NoYesSep 28, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-81841MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 29, 2026
CVE-2026-81842MEDIUM4.3
  • Grafana logoGrafana
  • grafana
NoYesSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management