Executive brief
parse-url is a widely-used JavaScript library for parsing and extracting components from URLs. A hostname confusion flaw in versions prior to 6.0.1 allows an attacker to craft malicious URLs that trick the parser into misidentifying the hostname, potentially exposing sensitive data like credentials embedded in URLs. This could compromise applications that rely on hostname validation for access control or security decisions.
Technical details
This vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and involves a hostname confusion issue in the parse-url library. The root cause stems from improper URL parsing logic that fails to correctly distinguish between the actual hostname and other URL components in certain edge cases. The vulnerability is remotely exploitable without authentication or user interaction—an attacker can supply a crafted URL to an application using the vulnerable parse-url library. By exploiting the confusion, an attacker can cause the library to misidentify the hostname, potentially allowing sensitive information embedded in the URL (such as credentials) to be mishandled or exposed. The vulnerability affects all versions prior to 6.0.1, which includes a fix addressing the hostname parsing logic. No active exploitation in the wild has been reported.
Affected products
- IonicaBizau parse-url prior to 6.0.1
Timeline
- 2022-06-27: disclosed: Vulnerability published on NVD
- 2022-06-27: patched: Fix released in version 6.0.1
- 2022-06-28: advisory: GHSA-4p35-cfcx-8653 published