{"id":"CVE-2018-12123","title":"Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed…","summary":"Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-115","CWE-20"],"vendor":"nodejs","product":"node.js","affected":["node.js >= 6.0.0, < 6.15.0","node.js >= 8.0.0, < 8.14.0","node.js >= 10.0.0, < 10.14.0","node.js >= 11.0.0, < 11.3.0"],"patched":["node.js 11.3.0"],"published":"2018-11-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:45.207","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-12123","references":[{"url":"https://access.redhat.com/errata/RHSA-2019:1821","label":"cve-request@iojs.org"},{"url":"https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/","label":"cve-request@iojs.org"},{"url":"https://security.gentoo.org/glsa/202003-48","label":"cve-request@iojs.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:1821","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202003-48","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20241213-0008/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0405,"epssPercentile":0.90375,"ingestedAt":"2026-10-08T23:16:47.295Z","slug":"CVE-2018-12123","body":"## Overview\n\nNode.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case \"javascript:\" (e.g. \"javAscript:\") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.\n\n## Affected\n\n- `node.js >= 6.0.0, < 6.15.0`\n- `node.js >= 8.0.0, < 8.14.0`\n- `node.js >= 10.0.0, < 10.14.0`\n- `node.js >= 11.0.0, < 11.3.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `node.js 11.3.0`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.8,"exploitation":0,"ransomware":0},"changes":[]}