Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-33290 | The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python). NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2022-0691 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-0686 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. NVD description · AI analysis pending | 9.1 | 2% | PoC |
| — | |
| CVE-2022-0639 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. NVD description · AI analysis pending | 5.3 | 2% | PoC |
| — | |
| CVE-2022-0512 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. NVD description · AI analysis pending | 5.3 | 2% | PoC |
| — | |
| CVE-2021-3664 | url-parse is vulnerable to URL Redirection to Untrusted Site url-parse is vulnerable to URL Redirection to Untrusted Site NVD description · AI analysis pending | 5.3 | 2% | PoC |
| — | |
| CVE-2021-27515 | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. NVD description · AI analysis pending | 5.3 | 2% | PoC |
| — | |
| CVE-2020-8124 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. NVD description · AI analysis pending | 5.3 | 2% | PoC |
| — | |
| CVE-2018-3774 | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol. NVD description · AI analysis pending | 10.0 | 4% |
| — |