Open Redirect in url-parse
Critical severity
GitHub Reviewed
Published
Aug 13, 2018
to the GitHub Advisory Database
•
Updated Jan 23, 2026
Description
Published to the GitHub Advisory Database
Aug 13, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 23, 2026
Versions of
url-parsebefore 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.Recommendation
Update to version 1.4.3 or later.
References