Lucene search

K
osvGoogleOSV:GHSA-RF54-44JR-Q5VF
HistoryMar 12, 2022 - 12:00 a.m.

Improper Input Validation in url-js

2022-03-1200:00:26
Google
osv.dev
8
improper input validation
url-js
vulnerability
parsing
spoofing
hostname
backslash
software

EPSS

0.001

Percentile

28.9%

The package url-js before 2.1.0 is vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\localhost and http://localhost are the same URL. However, the hostname is not parsed as localhost, and the backslash is reflected as it is.

EPSS

0.001

Percentile

28.9%

Related for OSV:GHSA-RF54-44JR-Q5VF