In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade uriparserUpgrade php85 | Jun 18, 2026 | May 8, 2026 |
| Amazon_linux_2023 | — | Upgrade php8.5-pdo-debuginfoUpgrade php8.5-bcmath-debuginfoUpgrade php8.5-xml-debuginfoUpgrade php8.5-sodium-debuginfoUpgrade php8.5-dbgUpgrade php8.5-gmp-debuginfoUpgrade php8.5-ldap-debuginfoUpgrade php8.5-enchantUpgrade php8.5-zip-debuginfoUpgrade php8.5-soapUpgrade php8.5-odbcUpgrade php8.5-mbstring-debuginfoUpgrade php8.5-commonUpgrade php8.5-intl-debuginfoUpgrade php8.5-mbstringUpgrade php8.5-fpm-debuginfoUpgrade php8.5-modphp-debuginfoUpgrade php8.5-embeddedUpgrade php8.5-process-debuginfoUpgrade php8.5-intlUpgrade php8.5-tidyUpgrade php8.5-processUpgrade php8.5-gdUpgrade php8.5-xmlUpgrade php8.5-fpmUpgrade php8.5-embedded-debuginfoUpgrade php8.5-ffi-debuginfoUpgrade php8.5-ldapUpgrade php8.5-pdoUpgrade php8.5Upgrade php8.5-develUpgrade php8.5-gmpUpgrade php8.5-bcmathUpgrade php8.5-pgsqlUpgrade php8.5-common-debuginfoUpgrade php8.5-snmpUpgrade php8.5-mysqlnd-debuginfoUpgrade php8.5-gd-debuginfoUpgrade php8.5-zipUpgrade php8.5-enchant-debuginfoUpgrade php8.5-modphpUpgrade php8.5-soap-debuginfoUpgrade php8.5-snmp-debuginfoUpgrade php8.5-debugsourceUpgrade php8.5-cli-debuginfoUpgrade php8.5-cliUpgrade php8.5-sodiumUpgrade php8.5-pgsql-debuginfoUpgrade php8.5-debuginfoUpgrade php8.5-dbaUpgrade php8.5-dbg-debuginfoUpgrade php8.5-odbc-debuginfoUpgrade php8.5-ffiUpgrade php8.5-dba-debuginfoUpgrade php8.5-tidy-debuginfoUpgrade php8.5-mysqlnd | May 28, 2026 | May 8, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub