Versions of url-parse before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.
Update to version 1.4.3 or later.
{
"github_reviewed": true,
"severity": "CRITICAL",
"cwe_ids": [
"CWE-425"
],
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T21:50:04Z"
}