CVE-2026-44928: uriparser 1.0.2 fixes CVE-2026-44927 and CVE-2026-44928
Published May 8, 2026
·Updated
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
Affected Software
2 affected components
uriparser uriparser<1.0.2
Uriparser Project Uriparser<1.0.2
Remediation
Patch Available
Event History
May 8, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44928?
CVE-2026-44928 has a medium severity rating due to the potential for misclassification of URIs.
2
How do I fix CVE-2026-44928?
To fix CVE-2026-44928, upgrade uriparser to version 1.0.2 or later.
3
What versions of uriparser are affected by CVE-2026-44928?
CVE-2026-44928 affects all versions of uriparser prior to 1.0.2.
4
What is the impact of CVE-2026-44928 on applications using uriparser?
Applications using affected versions of uriparser may incorrectly treat unequal URIs as equal, leading to potential security issues.
5
Is CVE-2026-44928 considered a critical vulnerability?
CVE-2026-44928 is not classified as critical, but it still poses a notable risk depending on the application's URI handling.