uriparser_project CVE Vulnerabilities & Metrics

Focus on uriparser_project vulnerabilities and metrics.

Last updated: 12 May 2026, 22:25 UTC

About uriparser_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with uriparser_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total uriparser_project CVEs: 10
Earliest CVE date: 12 Nov 2018, 15:29 UTC
Latest CVE date: 08 May 2026, 08:16 UTC

Latest CVE reference: CVE-2026-44928

Rolling Stats

30-day Count (Rolling): 2
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical uriparser_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.61

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 3
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS uriparser_project CVEs

These are the five CVEs with the highest CVSS scores for uriparser_project, sorted by severity first and recency.

All CVEs for uriparser_project

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

CVE-2021-46142 uriparser_project vulnerability CVSS: 4.3 06 Jan 2022, 04:15 UTC

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

CVE-2021-46141 uriparser_project vulnerability CVSS: 4.3 06 Jan 2022, 04:15 UTC

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

CVE-2018-20721 uriparser_project vulnerability CVSS: 7.5 16 Jan 2019, 14:29 UTC

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVE-2018-19200 uriparser_project vulnerability CVSS: 5.0 12 Nov 2018, 15:29 UTC

An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.

CVE-2018-19199 uriparser_project vulnerability CVSS: 7.5 12 Nov 2018, 15:29 UTC

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

CVE-2018-19198 uriparser_project vulnerability CVSS: 7.5 12 Nov 2018, 15:29 UTC

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.