CVE-2022-0691: Url-Parse Project Url-Parse

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

Affected products

Published 2022-02-21. Last modified 2026-06-17.