Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 42: uriparser CVE-2025-67899 Fix for Unbounded Recursion Issue

fedora
Calendar Grey December 21, 2025
Dist Fedora Esm H88
Update for uriparser to fix unbounded recursion issue. Learn about the security advisory for Fedora 42.
Update to uriparser-1.0.0, fixes CVE-2025-67899.

Summary

Uriparser is a strictly RFC 3986 compliant URI parsing library written

in C. uriparser is cross-platform, fast, supports Unicode and is

licensed under the New BSD license.

Update Information:

Update to uriparser-1.0.0, fixes CVE-2025-67899.

Change Log

* Mon Dec 15 2025 Sandro Mani - 1.0.0-1 - Update to 1.0.0 * Thu Sep 4 2025 Sandro Mani - 0.9.9-1 - Update to 0.9.9 * Fri Jul 25 2025 Fedora Release Engineering - 0.9.8-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild

References


[ 1 ] Bug #2423026 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2423026 [ 2 ] Bug #2423027 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423027

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-bf69e91bda' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: uriparser
Product: Fedora 42
Version: 1.0.0
Release: 1.fc42
Summary: URI parsing library - RFC 3986

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here