Vendorsurl-parse Projecturl-parseany version
Vulnerabilities

url-parse Project url-parse 0.0.4 for Node.js any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2018-3774
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
Published 2018-08-12 · Modified
10.0EPSS 0.038
CVE-2022-0691
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published 2022-02-21 · Modified
9.8EPSS 0.022
CVE-2022-0686
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published 2022-02-20 · Modified
9.1EPSS 0.018
CVE-2022-0512
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published 2022-02-14 · Modified
8.8EPSS 0.018
CVE-2022-0639
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published 2022-02-17 · Modified
6.5EPSS 0.015
CVE-2021-27515
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Published 2021-02-21 · Modified
5.3EPSS 0.020
CVE-2021-3664
Open Redirect in unshiftio/url-parse
Published 2021-07-26 · Modified
5.3EPSS 0.018
CVE-2020-8124
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
Published 2020-02-04 · Modified
5.3EPSS 0.017