unshiftio/url-parse

unshiftio/url-parse

Releases49
Frequency1 month 3 weeks
Last Release
Stars1.04K
Small footprint URL parser that works seamlessly across Node.js and browser environments.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

9.1 CRITICAL6.4 MEDIUM

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

5.3 MEDIUM5 MEDIUM

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

5.3 MEDIUM5 MEDIUM

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

5.3 MEDIUM5 MEDIUM

url-parse is vulnerable to URL Redirection to Untrusted Site

5.3 MEDIUM5 MEDIUM

url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

7.5 HIGH

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.