← back
CVE-2018-3774CWE-425

CVE-2018-3774

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.8%
exploitation probability
3.8%top 11% of all CVEs
observed exploitation
nono source reports it
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
Affected products
HackerOne · url-parse