{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93751.json"}],"title":"uri-js: uri-js: Improper UTF-8 decoding allows path traversal and CRLF injection","tracking":{"current_release_date":"2026-09-23T15:01:40+00:00","generator":{"date":"2026-09-23T15:01:40+00:00","engine":{"name":"Red Hat SDEngine","version":"5.4.0"}},"id":"CVE-2026-93751","initial_release_date":"2026-09-18T17:51:36.332000+00:00","revision_history":[{"date":"2026-09-18T17:51:36.332000+00:00","number":"1","summary":"Initial version"},{"date":"2026-09-22T16:44:53.375297+00:00","number":"2","summary":"Current version"},{"date":"2026-09-23T15:01:40+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat Hardened Images","product":{"name":"Red Hat Hardened Images","product_id":"red_hat_hardened_images","product_identification_helper":{"cpe":"cpe:/a:redhat:hummingbird:1"}}}],"category":"product_family","name":"Red Hat Hardened Images"},{"category":"product_version","name":"dotnet8.0.src","product":{"name":"dotnet8.0.src","product_id":"dotnet8.0.src","product_identification_helper":{"purl":"pkg:rpm/redhat/dotnet8.0@8.0.130-0.1.hum1?arch=src"}}},{"category":"product_version","name":"grafana12.4.src","product":{"name":"grafana12.4.src","product_id":"grafana12.4.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana12.4@12.4.10-0.6.hum1?arch=src"}}},{"category":"product_version","name":"grafana13.1.src","product":{"name":"grafana13.1.src","product_id":"grafana13.1.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana13.1@13.1.6-0.2.hum1?arch=src"}}},{"category":"product_version","name":"grafana13.2.src","product":{"name":"grafana13.2.src","product_id":"grafana13.2.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana13.2@13.2.1-0.5.hum1?arch=src"}}},{"category":"product_version","name":"jaeger.src","product":{"name":"jaeger.src","product_id":"jaeger.src","product_identification_helper":{"purl":"pkg:rpm/redhat/jaeger@2.20.0-0.11.hum1?arch=src"}}},{"category":"product_version","name":"opentelemetry-collector.src","product":{"name":"opentelemetry-collector.src","product_id":"opentelemetry-collector.src","product_identification_helper":{"purl":"pkg:rpm/redhat/opentelemetry-collector@0.161.0-0.1.hum1?arch=src"}}},{"category":"product_version","name":"opentelemetry-collector-contrib.src","product":{"name":"opentelemetry-collector-contrib.src","product_id":"opentelemetry-collector-contrib.src","product_identification_helper":{"purl":"pkg:rpm/redhat/opentelemetry-collector-contrib@0.161.0-0.1.hum1?arch=src"}}},{"category":"product_version","name":"opentelemetry-collector-k8s.src","product":{"name":"opentelemetry-collector-k8s.src","product_id":"opentelemetry-collector-k8s.src","product_identification_helper":{"purl":"pkg:rpm/redhat/opentelemetry-collector-k8s@0.161.0-0.1.hum1?arch=src"}}},{"category":"product_version","name":"prometheus3.13.src","product":{"name":"prometheus3.13.src","product_id":"prometheus3.13.src","product_identification_helper":{"purl":"pkg:rpm/redhat/prometheus3.13@3.13.3-0.1.hum1?arch=src"}}},{"category":"product_version","name":"rust.src","product":{"name":"rust.src","product_id":"rust.src","product_identification_helper":{"purl":"pkg:rpm/redhat/rust@1.98.1-1.hum1?arch=src"}}}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"dotnet8.0.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:dotnet8.0.src"},"product_reference":"dotnet8.0.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"grafana12.4.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:grafana12.4.src"},"product_reference":"grafana12.4.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"grafana13.1.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:grafana13.1.src"},"product_reference":"grafana13.1.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"grafana13.2.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:grafana13.2.src"},"product_reference":"grafana13.2.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"jaeger.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:jaeger.src"},"product_reference":"jaeger.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"opentelemetry-collector-contrib.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:opentelemetry-collector-contrib.src"},"product_reference":"opentelemetry-collector-contrib.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"opentelemetry-collector-k8s.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:opentelemetry-collector-k8s.src"},"product_reference":"opentelemetry-collector-k8s.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"opentelemetry-collector.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:opentelemetry-collector.src"},"product_reference":"opentelemetry-collector.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"prometheus3.13.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:prometheus3.13.src"},"product_reference":"prometheus3.13.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"rust.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:rust.src"},"product_reference":"rust.src","relates_to_product_reference":"red_hat_hardened_images"}]},"vulnerabilities":[{"cve":"CVE-2026-93751","cwe":{"id":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"},"discovery_date":"2026-09-22T15:43:01.970465+00:00","flags":[{"label":"component_not_present","product_ids":["red_hat_hardened_images:jaeger.src","red_hat_hardened_images:prometheus3.13.src"]}],"ids":[{"system_name":"Red Hat Bugzilla ID","text":"2537856"}],"notes":[{"category":"description","text":"A flaw was found in uri-js. This improper UTF-8 (Unicode Transformation Format - 8-bit) decoding vulnerability in the `pctDecChars()` function allows a remote attacker to craft specially encoded payloads. These payloads can bypass platform decoder validation, leading to the injection of path traversal or Carriage Return Line Feed (CRLF) sequences. This could enable attackers to access unauthorized files or manipulate application logs and HTTP responses.","title":"Vulnerability description"},{"category":"summary","text":"uri-js: uri-js: Improper UTF-8 decoding allows path traversal and CRLF injection","title":"Vulnerability summary"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"known_affected":["red_hat_hardened_images:dotnet8.0.src","red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:opentelemetry-collector-contrib.src","red_hat_hardened_images:opentelemetry-collector-k8s.src","red_hat_hardened_images:opentelemetry-collector.src","red_hat_hardened_images:rust.src"],"known_not_affected":["red_hat_hardened_images:jaeger.src","red_hat_hardened_images:prometheus3.13.src"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-93751"},{"category":"external","summary":"RHBZ#2537856","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2537856"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-93751","url":"https://www.cve.org/CVERecord?id=CVE-2026-93751"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-93751","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93751"},{"category":"external","summary":"https://github.com/garycourt/uri-js","url":"https://github.com/garycourt/uri-js"},{"category":"external","summary":"https://github.com/garycourt/uri-js/blob/a1acf730b4bba3f1097c9f52e7d9d3aba8cdcaae/src/uri.ts#L103-L141","url":"https://github.com/garycourt/uri-js/blob/a1acf730b4bba3f1097c9f52e7d9d3aba8cdcaae/src/uri.ts#L103-L141"},{"category":"external","summary":"https://github.com/garycourt/uri-js/issues/106","url":"https://github.com/garycourt/uri-js/issues/106"},{"category":"external","summary":"https://www.vulncheck.com/advisories/uri-js-through-4.4.1-improper-utf-8-decoding-via-pctdecchars","url":"https://www.vulncheck.com/advisories/uri-js-through-4.4.1-improper-utf-8-decoding-via-pctdecchars"}],"release_date":"2026-09-18T17:51:36.332000+00:00","remediations":[{"category":"none_available","details":"Affected","product_ids":["red_hat_hardened_images:dotnet8.0.src","red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:opentelemetry-collector-contrib.src","red_hat_hardened_images:opentelemetry-collector-k8s.src","red_hat_hardened_images:opentelemetry-collector.src","red_hat_hardened_images:rust.src"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["red_hat_hardened_images:dotnet8.0.src","red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:jaeger.src","red_hat_hardened_images:opentelemetry-collector-contrib.src","red_hat_hardened_images:opentelemetry-collector-k8s.src","red_hat_hardened_images:opentelemetry-collector.src","red_hat_hardened_images:prometheus3.13.src","red_hat_hardened_images:rust.src"]}],"threats":[{"category":"impact","details":"Moderate","product_ids":["red_hat_hardened_images:dotnet8.0.src","red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:jaeger.src","red_hat_hardened_images:opentelemetry-collector-contrib.src","red_hat_hardened_images:opentelemetry-collector-k8s.src","red_hat_hardened_images:opentelemetry-collector.src","red_hat_hardened_images:prometheus3.13.src","red_hat_hardened_images:rust.src"]}],"title":"uri-js: uri-js: Improper UTF-8 decoding allows path traversal and CRLF injection"}]}