CVE-2018-3774: Url-Parse Project Url-Parse

Critical severity, CVSS 10.0. EPSS: 3.8% chance of exploitation in the next 30 days.

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.

Affected products

Published 2018-08-12. Last modified 2026-06-17.