CVE-2022-0691: Url-Parse Project Url-Parse
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
Affected products
- Url-Parse Project Url-Parse: before 1.5.9 (fixed in 1.5.9)
Published 2022-02-21. Last modified 2026-06-17.