CVE-2018-20721: Debian Linux
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Uriparser Project Uriparser: before 0.9.1 (fixed in 0.9.1)
Published 2019-01-16. Last modified 2026-06-17.