CVE-2026-45822

Updated on 30 Jun 2026

Severity

6.6 Medium severity

Details

CVSS score
6.6
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber

Overview

About vulnerability

Impact

An attacker who can supply input to decodeUriComponent() (directly or via a dependency that uses this package on URL/query/path data) can cause excessive CPU usage and application unresponsiveness. This is an availability issue; there is no known memory corruption, data disclosure, or remote code execution impact.

Patches

Upgrade to [email protected].

Workarounds

Limit the size of the input.

Details

Affected product:
AngularJS , Babel , Next.js , Node.js , React , Vue , anymatch , apollo , appkit , babel-loader , babel-plugin-add-module-exports , bin-wrapper , braces , broccoli , cache-loader , cacheable-request , celo-celocli , celo-connect , celo-contractkit , celo-dev-utils , celo-encrypted-backup , celo-explorer , celo-governance , celo-identity , celo-phone-number-privacy-common , chokidar , codeshift-core , compare-urls , core-js , create-expo-module , critters , css , css-loader , decode-uri-component , developer-tooling , devkit , documentation , ember-cli , ember-cli/broccoli-sane-watcher , eslint-loader , eth-lib , expand-brackets , expo , extglob , extract-css-chunks-webpack-plugin , extract-text-webpack-plugin , fast-glob , file-loader , findup-sync , fork-ts-checker-webpack-plugin , friendly-errors-webpack-plugin , gatsby , get-workspaces , gh-got , git-up , git-url-parse , glob-watcher , globby , googlemaps-google-maps-services-js , got , gulp , gulp-cli , hard-source-webpack-plugin , html-webpack-plugin , http-proxy-middleware , imagemin , imagemin-mozjpeg , imagemin-pngquant , ionic-v1-toolkit , istanbul-instrumenter-loader , jest , jest-repl , jest-watch-typeahead , jovidecroock-prefresh , js-matchdep , jscodeshift , karma , kesla/download-tarball , kevva/download , liftoff , magic-js , micromatch , mini-css-extract-plugin , minimizer-webpack-plugin , modern.js , mozjpeg-bin , nanomatch , nguniversal , nicolo-ribaudo-chokidar-2 , normalize-url , npm:@blockshake/defly-connect , null-loader , nuxt , onflow-fcl-rainbowkit-adapter , open-wc-testing-karma , opencensus-node , optimize-css-assets-webpack-plugin , parcel-bundler , parse-path , parse-url , pngquant-bin , porto , postcss-loader , prefresh-webpack , preload-webpack-plugin , privy-io , progress-bar-webpack-plugin , query-string , qunit , rainbowkit , readdirp , releaser-tools , resolve-url-loader , rework , rollup-plugin-sourcemaps , rushstack , rushstack-hashed-folder-copy-plugin , rushstack-heft-webpack4-plugin , rushstack-webpack4-localization-plugin , rushstack-webpack4-module-minifier-plugin , sane , sass-loader , schema-utils , script-ext-html-webpack-plugin , snapdragon , source-map-resolve , style-loader , style-resources-loader , stylus , swarm-js , thread-loader , time-fix-plugin , uglifyjs-webpack-plugin , unified-args , url-loader , use-wallet , wagmi , wagmi-connectors , walletconnect-monorepo , watcher , watchpack , web-test-runner-saucelabs , web3.js , web3modal , webdriverio , webpack , webpack-dev-middleware , webpack-dev-server , webpack-manifest-plugin , webpack-subresource-integrity , webpackbar , x402 , xhr-request , xhr-request-promise
Affected packages:
expo-router @ 58.0.4 (+1556 more)

Fixes