Junglewise Threat Intelligence

CVE-2026-44928: uriparser incorrect URI comparison in EqualsUri

CVE-2026-44928 · Severity: low · CVSS 2.9 · Published 2026-05-08

Technologies: Uriparser Project Uriparser. Vendors: Uriparser Project.

Executive brief

A vulnerability exists in uriparser, a widely used library for processing web addresses (URIs). The software may incorrectly identify two different web addresses as being identical. This flaw could allow an attacker to bypass security filters or access controls that rely on URI comparison to protect sensitive data or restrict user actions.

Technical details

A logic error exists in the EqualsUri function family within uriparser before version 1.0.2. Specifically, the implementation fails to correctly account for the .absolutePath property during comparison, leading to incorrect equality results (CWE-670). An attacker could exploit this by providing specially crafted URIs to an application that uses uriparser for security-critical decisions, such as allowlist validation or origin checking. This could result in unauthorized access or bypass of security restrictions. The issue is resolved in version 1.0.2.

Affected products

  • uriparser project uriparser < 1.0.2

Timeline

  • 2026-05-04: other: Vulnerability identified and fix proposed in pull request
  • 2026-05-08: disclosed: CVE-2026-44928 published
  • 2026-05-08: patched: Fix merged into master branch and included in version 1.0.2

References

Related threats