Executive brief
parse-url is a popular npm library used to parse and normalize URLs in Node.js applications. The library incorrectly parses certain HTTP and HTTPS URLs, misidentifying the protocol as SSH and potentially spoofing hostnames. An attacker could exploit this by crafting malicious URLs to bypass URL validation, redirect traffic to attacker-controlled servers, or trick applications into connecting to wrong hosts.
Technical details
parse-url prior to version 8.1.0 contains a misinterpretation of input vulnerability (CWE-115) in its URL parsing logic. The library fails to correctly parse certain HTTP or HTTPS URLs, sometimes identifying the protocol as SSH instead, and may also parse the hostname incorrectly. The vulnerability is triggered when processing specially crafted URLs and requires no authentication or special privileges. An attacker can exploit this by providing malicious URLs to an application that uses parse-url for validation or redirection, potentially causing hostname spoofing attacks. The fix was released in version 8.1.0.
Affected products
- Ionic Bizau parse-url prior to 8.1.0
Timeline
- 2022-09-16: disclosed: Advisory published
- 2022-09-16: patched: Version 8.1.0 released with fix