GHSA-8v38-pw62-9cw2
url-parse Incorrectly parses URLs that include an '@'
Quick fix
GHSA-8v38-pw62-9cw2 — url-parse: upgrade to the fixed version with the command below.
npm install url-parse@1.5.7Details
A specially crafted URL with an '@' sign but empty user info and no hostname, when parsed with url-parse, url-parse will return the incorrect href. In particular,
```js parse(\"http://@/127.0.0.1\") ``` Will return: ```yaml { slashes: true, protocol: 'http:', hash: '', query: '', pathname: '/127.0.0.1', auth: '', host: '', port: '', hostname: '', password: '', username: '', origin: 'null', href: 'http:///127.0.0.1' } ``` If the 'hostname' or 'origin' attributes of the output from url-parse are used in security decisions and the final 'href' attribute of the output is then used to make a request, the decision may be incorrect.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0639[ADVISORY]
- https://github.com/unshiftio/url-parse/commit/ef45a1355375a8244063793a19059b4f62fc8788[WEB]
- https://github.com/unshiftio/url-parse[PACKAGE]
- https://huntr.dev/bounties/83a6bc9a-b542-4a38-82cd-d995a1481155[WEB]
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html[WEB]
- https://lists.debian.org/debian-lts-announce/2025/12/msg00024.html[WEB]