CVE-2025-67899

Updated: 2025-12-18 23:33:18.733643

Description:

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x LOW 2.9

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 7 ELS php 5.4.16 2.9 LOW Ignored 2025-12-24 04:23:31
RHEL 7 ELS php 5.4.16 2.9 LOW Ignored 2025-12-24 04:23:30
TuxCare 9.6 ESU php 8.0.30 2.9 LOW Ignored 2025-12-25 14:35:24
Ubuntu 16.04 ELS php 7.0.33 2.9 LOW Ignored 2026-01-17 01:22:58 This is a local-only, high‑complexity stack‑exhaustion in uriparser that requires an application...
Ubuntu 18.04 ELS php 7.2.24-0 2.9 LOW Ignored 2026-01-17 01:22:59 This is a local-only, high‑complexity stack‑exhaustion in uriparser that requires an application...
Ubuntu 20.04 ELS php 7.4.3 2.9 LOW Ignored 2026-01-17 01:22:59 This is a local-only, high‑complexity stack‑exhaustion in uriparser that requires an application...
Total: 16