Junglewise Threat Intelligence

CVE-2022-25839: url-js improper input validation in hostname parsing

CVE-2022-25839 · Severity: low · CVSS 3.1 · Published 2022-03-12

Vendors: npm.

Executive brief

url-js is a JavaScript library for parsing and manipulating URLs. A flaw in how it processes URLs containing backslashes allows an attacker to bypass hostname validation checks by spoofing the hostname—for example, treating "http://\\\\localhost" as a different host than "http://localhost". This could enable attackers to bypass security controls that check for specific hostnames, such as redirect validation or allowlist enforcement.

Technical details

The vulnerability is an improper input validation flaw (CWE-20) in the URL parsing logic of url-js. The root cause is inadequate handling of backslash characters during hostname extraction, allowing URLs with escaped backslashes to bypass canonical hostname checks. An unauthenticated remote attacker can craft a malicious URL with backslashes and send it to an application that uses url-js for hostname validation without user interaction required. The attacker can achieve hostname spoofing to circumvent access controls or redirect validation. The issue was fixed in version 2.1.0; all prior versions are affected.

Affected products

  • url-js contributors url-js before 2.1.0

Timeline

  • 2022-03-12: disclosed
  • 2022-03-12: patched: Fixed in version 2.1.0

References