CVE-2025-67899: Uriparser Project Uriparser

Low severity, CVSS 2.9. EPSS: 0.1% chance of exploitation in the next 30 days.

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Affected products

Published 2025-12-14. Last modified 2026-06-17.