Junglewise Threat Intelligence

CVE-2021-27516: URIjs hostname spoofing via backslashes

CVE-2021-27516 · Severity: low · CVSS 3.1 · Published 2021-03-01

Technologies: Medialize Urijs. Vendors: npm.

Executive brief

URIjs is a JavaScript library used to parse and manipulate URLs in web applications. The library incorrectly handles backslash characters in URLs, allowing attackers to spoof the hostname component. If an application relies on URIjs to validate or enforce security policies based on hostname (such as allow/block lists or access controls), an attacker could bypass these protections, potentially leading to unauthorized access or redirects to malicious sites.

Technical details

The vulnerability is an improper input validation issue (CWE-20) in URL parsing where backslashes in the scheme delimiter are not properly handled. Affected versions of URIjs parse URLs like "https:/\expected-example.com" as having no hostname, whereas the correct behavior (per WHATWG URL specification) is to extract "expected-example.com". The attack vector is network-based with no authentication or user interaction required—an attacker simply crafts a malicious URL and causes an application using URIjs to parse it. Depending on how the application uses the parsed hostname, impacts include bypass of security allow/block lists, Server-Side Request Forgery (SSRF) attacks, and open redirects. Version 1.19.6 and later patch this issue to align with WHATWG URL specification compliance and browser behavior.

Affected products

  • medialize URIjs before 1.19.6

Timeline

  • 2021-02-22: disclosed
  • 2021-03-01: advisory
  • 2021: patched: Version 1.19.6 released with fix

References

Related threats