Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-4101 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect. |
Ubuntu USN |
USN-4796-1 | Node.js vulnerabilities |
Fri, 09 Oct 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: nodejs
Published:
Updated: 2026-10-08T21:14:00.915Z
Reserved: 2018-06-11T00:00:00.000Z
Link: CVE-2018-12123
Updated: 2024-12-13T13:09:21.262Z
Status : Modified
Published: 2018-11-28T17:29:00.417
Modified: 2026-10-08T22:16:45.207
Link: CVE-2018-12123
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN