Unbounded Recursion Vulnerability in uriparser Affects Various Applications
CVE-2025-67899

2.9LOW

Key Information:

Status
Vendor
CVE Published:
14 December 2025

What is CVE-2025-67899?

The vulnerability in uriparser allows for unbounded recursion, which can lead to excessive stack consumption when large input containing multiple commas is processed. This flaw compromises the stability and performance of applications utilizing uriparser for URI parsing, potentially resulting in crashes or denial-of-service conditions. Developers and organizations using this library should evaluate their implementations and apply patches or mitigations to avoid exploitation.

Affected Version(s)

uriparser 0 <= 0.9.9

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67899 : Unbounded Recursion Vulnerability in uriparser Affects Various Applications