---
id: CVE-2018-12123
title: >-
  Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0:
  Hostname spoofing in URL parser for javascript protocol: If a Node.js
  application is using url.parse() to determine the URL hostname, that hostname
  can be spoofed…
summary: >-
  Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0:
  Hostname spoofing in URL parser for javascript protocol: If a Node.js
  application is using url.parse() to determine the URL hostname, that hostname
  can be spoofed…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-115
  - CWE-20
vendor: nodejs
product: node.js
affected:
  - 'node.js >= 6.0.0, < 6.15.0'
  - 'node.js >= 8.0.0, < 8.14.0'
  - 'node.js >= 10.0.0, < 10.14.0'
  - 'node.js >= 11.0.0, < 11.3.0'
patched:
  - node.js 11.3.0
published: '2018-11-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:45.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-12123'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2019:1821'
    label: cve-request@iojs.org
  - url: 'https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/'
    label: cve-request@iojs.org
  - url: 'https://security.gentoo.org/glsa/202003-48'
    label: cve-request@iojs.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:1821'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202003-48'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20241213-0008/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0405
epssPercentile: 0.90375
ingestedAt: '2026-10-08T23:16:47.295Z'
---

## Overview

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.

## Affected

- `node.js >= 6.0.0, < 6.15.0`
- `node.js >= 8.0.0, < 8.14.0`
- `node.js >= 10.0.0, < 10.14.0`
- `node.js >= 11.0.0, < 11.3.0`

## Remediation

Upgrade past the affected range:

- `node.js 11.3.0`
