{"id":"AZL-92075","summary":"CVE-2026-45822 affecting package js-jquery 3.5.0-4","details":"decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.","modified":"2026-08-30T05:24:52Z","published":"2026-06-30T09:16:25Z","upstream":["CVE-2026-45822"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45822"}],"affected":[{"package":{"name":"js-jquery","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/js-jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.5.0-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92075.json"}}],"schema_version":"1.9.0"}