Medium severity5.3NVD Advisory· Published Mar 3, 2022· Updated Jun 17, 2026
CVE-2022-24723
CVE-2022-24723
Description
URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
urijsnpm | < 1.19.9 | 1.19.9 |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/medialize/uri.js/commit/86d10523a6f6e8dc4300d99d671335ee362ad316nvdPatchThird Party Advisory
- huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/advisories/GHSA-gmv4-r438-p67fghsaADVISORY
- github.com/medialize/URI.js/releases/tag/v1.19.9nvdRelease NotesThird Party AdvisoryWEB
- github.com/medialize/URI.js/security/advisories/GHSA-gmv4-r438-p67fnvdMitigationThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-24723ghsaADVISORY
- github.com/medialize/URI.js/commit/86d10523a6f6e8dc4300d99d671335ee362ad316ghsaWEB
- huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5ghsaWEB
News mentions
0No linked articles in our index yet.