CVE-2018-3774: Url-Parse Project Url-Parse
Critical severity, CVSS 10.0. EPSS: 3.8% chance of exploitation in the next 30 days.
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
Affected products
- Url-Parse Project Url-Parse: before 1.4.3 (fixed in 1.4.3)
Published 2018-08-12. Last modified 2026-06-17.