Npm · Url-Parse · CVE-2018-3774
**Name of the Vulnerable Software and Affected Versions**
url-parse versions prior to 1.4.3
**Description**
The issue is related to incorrect parsing in url-parse, which returns the wrong hostname. This can lead to multiple vulnerabilities, including Server Side Request Forgery (SSRF), Open Redirect, and Bypass Authentication Protocol.
**Recommendations**
Update to version 1.4.3 or later.