VDB
Sign up
MEDIUM6.1

GHSA-pqw5-jmp5-px4v

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing

Quick fix

GHSA-pqw5-jmp5-px4v — parse-url: upgrade to the fixed version with the command below.

npm install parse-url@8.1.0

Details

parse-url prior to 8.1.0 is vulnerable to Misinterpretation of Input. parse-url parses certain http or https URLs incorrectly, identifying the URL's protocol as ssh. It may also parse the host name incorrectly.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-url
Introduced in: 0Fixed in: 8.1.0
Fixnpm install parse-url@8.1.0

References