url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.
{ "affected_functions": [ "(url-parse).Url" ] }