ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-33290
The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue

The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).

NVD description · AI analysis pending
7.5<1% PoC
  • git-url-parse project git-url-parse
CVE-2022-0691
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

NVD description · AI analysis pending
9.82% PoC
  • url-parse project url-parse
CVE-2022-0686
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

NVD description · AI analysis pending
9.12% PoC
  • url-parse project url-parse
CVE-2022-0639
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

NVD description · AI analysis pending
5.32% PoC
  • url-parse project url-parse
CVE-2022-0512
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

NVD description · AI analysis pending
5.32% PoC
  • url-parse project url-parse
CVE-2021-3664
url-parse is vulnerable to URL Redirection to Untrusted Site

url-parse is vulnerable to URL Redirection to Untrusted Site

NVD description · AI analysis pending
5.32% PoC
  • url-parse project url-parse
CVE-2021-27515
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

NVD description · AI analysis pending
5.32% PoC
  • url-parse project url-parse
CVE-2020-8124
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

NVD description · AI analysis pending
5.32% PoC
  • url-parse project url-parse
CVE-2018-3774
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.

NVD description · AI analysis pending
10.04%
  • url-parse project url-parse