CVE-2024-34402: Fedoraproject Fedora
High severity, CVSS 8.6. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
Affected products
- Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
- Uriparser Project Uriparser: up to and including 0.9.7
Published 2024-05-03. Last modified 2026-06-17.