logo

Database

Lack of data validation In parse-url

Description

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing parse-url prior to 8.1.0 is vulnerable to Misinterpretation of Input. parse-url parses certain http or https URLs incorrectly, identifying the URL's protocol as ssh. It may also parse the host name incorrectly.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-UW2FK – Vulnerability | Fluid Attacks Database