A medium-severity denial-of-service vulnerability, tracked as CVE-2026-45822 with a CVSS score of 6.6, affects the decode-uri-component package. The flaw arises from exponential decoding of malformed percent-encoded input in the decodeUriComponent function, which can lead to excessive CPU usage and application unresponsiveness when an attacker supplies malicious input. This results in an availability issue without any known memory corruption, data disclosure, or remote code execution impact. Affected versions include decode-uri-component: <= 0.4.2. The vulnerability is exploitable via network attacks with low complexity and no user interaction required. Business impact includes potential application downtime and loss of productivity due to unresponsiveness.
We recommend you to update decode-uri-component to version 0.5.0.[/subscribe_to_unlock_form]
A medium-severity denial-of-service vulnerability, tracked as CVE-2026-45822 with a CVSS score of 6.6, affects the decode-uri-component package. The flaw arises from exponential decoding of malformed percent-encoded input in the decodeUriComponent function, which can lead to excessive CPU usage and application unresponsiveness when an attacker supplies malicious input. This results in an availability issue without any known memory corruption, data disclosure, or remote code execution impact. Affected versions include decode-uri-component: <= 0.4.2. The vulnerability is exploitable via network attacks with low complexity and no user interaction required. Business impact includes potential application downtime and loss of productivity due to unresponsiveness.
We recommend you to update decode-uri-component to version 0.5.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]