The Url Js Project maintains a lightweight URL-parsing library with a narrow product scope, focused on handling the parsing and manipulation of uniform resource locators in web applications. Given the essential but tightly scoped nature of the library, track its updates alongside other foundational web utilities your environment depends on; current CVE counts and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Url Js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25839MEDIUM The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\local | Mar 11, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Url Js Project.
Media articles that mention a CVE ID that affects a product developed by Url Js Project — matched by CVE ID, not by vendor name.