{"id":"CVE-2021-27515","aliases":["GHSA-9m6j-fcg5-2442"],"url":"https://o3.security/vulnerability/CVE-2021-27515","summary":"Path traversal in url-parse","details":"url-parse before 1.5.0 mishandles certain uses of backslash such as http:\\/ and interprets the URI as a relative path.","published":"2021-02-22T00:15:12.543Z","modified":"2026-07-09T00:13:21.483096Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"url-parse","fixedVersion":"1.5.0"}],"fix":{"url":"https://github.com/unshiftio/url-parse/commit/d1e7e8822f26e8a49794b757123b51386325b2b0","label":"unshiftio/url-parse@d1e7e88"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html"},{"type":"FIX","url":"https://github.com/unshiftio/url-parse/commit/d1e7e8822f26e8a49794b757123b51386325b2b0"},{"type":"FIX","url":"https://github.com/unshiftio/url-parse/compare/1.4.7...1.5.0"},{"type":"FIX","url":"https://github.com/unshiftio/url-parse/pull/197"},{"type":"EVIDENCE","url":"https://advisory.checkmarx.net/advisory/CX-2021-4306"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:13:21.483096Z"}}