{"id":"UBUNTU-CVE-2026-45822","details":"decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.","modified":"2026-07-01T21:24:53Z","published":"2026-06-30T09:16:00Z","upstream":["CVE-2026-45822"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-45822"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-45822"},{"type":"REPORT","url":"https://github.com/SamVerschueren/decode-uri-component/blob/00662938dc7c6241547ae8abce7785cc13ffd3f6/index.js"},{"type":"REPORT","url":"https://github.com/SamVerschueren/decode-uri-component/commit/fa479dafeede7bedf04e5c89aa78f2a78c664005"},{"type":"REPORT","url":"https://www.npmjs.com/package/decode-uri-component"}],"affected":[{"package":{"name":"node-source-map-resolve","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/node-source-map-resolve?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.0+~cs2.7.2-2","0.6.0+~cs2.7.3-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.6.0+~cs2.7.3-2","binary_name":"node-source-map-resolve"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45822.json"}},{"package":{"name":"node-source-map-resolve","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/node-source-map-resolve?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.0+~cs2.7.3-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.6.0+~cs2.7.3-2","binary_name":"node-source-map-resolve"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45822.json"}},{"package":{"name":"node-source-map-resolve","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/node-source-map-resolve?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.0+~cs2.7.3-2"],"ecosystem_specific":{"binaries":[{"binary_name":"node-source-map-resolve","binary_version":"0.6.0+~cs2.7.3-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45822.json"}},{"package":{"name":"node-source-map-resolve","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/node-source-map-resolve?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.0+~cs2.7.3-2"],"ecosystem_specific":{"binaries":[{"binary_name":"node-source-map-resolve","binary_version":"0.6.0+~cs2.7.3-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45822.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:Y/R:U/V:D/RE:M/U:Amber"},{"type":"Ubuntu","score":"medium"}]}