Executive brief
url-parse is a JavaScript library used to parse and validate URLs in web applications and services. Versions before 1.4.3 incorrectly parse certain malformed URLs, returning wrong hostname values that attackers can exploit to redirect users to unintended sites, bypass authentication checks, or trigger server-side requests to internal systems.
Technical details
url-parse versions 1.0.0 through 1.4.2 contain a hostname parsing vulnerability that can be exploited via specially crafted URLs. The library's instruction-based parsing logic fails to correctly validate and extract the hostname component, allowing an attacker to inject or obscure the actual target hostname. This is a network-reachable vulnerability with no authentication required—an attacker can craft a malicious URL and serve it to a user or application that uses url-parse. Successful exploitation leads to open redirect, SSRF, or authentication bypass depending on how the parsed URL is used downstream. The vulnerability was fixed in version 1.4.3.
Affected products
- unshiftio url-parse 1.0.0 to 1.4.2
Timeline
- 2018-08-13: disclosed
- 2018: patched: Fix released in version 1.4.3