An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "target": { "file": "src/UriCommon.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "238694713258322115303681988687386408516", "333926045229699897286472797433355283244", "138300199436163588087688100460718751407", "111266075995237801075582346262922185341" ], "threshold": 0.9 }, "id": "CVE-2018-19200-1bdea374", "source": "https://github.com/uriparser/uriparser/commit/f58c25069cf4a986fe17a80c5b38687e31feb539" } ] }