oss-sec mailing list archives

uriparser 1.0.1 fixes CVE-2026-42371 (integer overflow)


From: Sebastian Pipping <sebastian () pipping org>
Date: Mon, 27 Apr 2026 14:57:36 +0200

Hello oss-security,


just a quick note that uriparser 1.0.1 released today is fixing
CVE-2026-42371: integer overflow in text range comparison.

Some key links are:

- The change log of release 1.0.1
  https://github.com/uriparser/uriparser/blob/uriparser-1.0.1/ChangeLog

- The fixing pull request
  https://github.com/uriparser/uriparser/pull/298

- The official CVE metadata
  https://nvd.nist.gov/vuln/detail/CVE-2026-42371

Best



Sebastian


Current thread: