Shazzer logo

Characters allowed in between // in absolute URL

Safari logo 1
Edge logo 1
Firefox logo 1
Chrome logo 1

Characters allowed in between // in absolute URL

Created by: bribes

Created on: Saturday, November 29, 2025 at 3:38:51 AM

Updated on: Saturday, November 29, 2025 at 3:38:51 AM


Category: URL Handling

Vector visibility: Public

Vector type: JS

Vector charset: UTF-8

Template used:
let chr = String.fromCodePoint($[i]);0x0D
let a = document.createElement("a");0x0D
a.href = '/'+chr+'/example.com';0x0D
new URL(a.href).host === "example.com" && log($[i])
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

let chr = String.fromCodePoint(0);0x0D
let a = document.createElement("a");0x0D
a.href = '/'+chr+'/example.com';0x0D
new URL(a.href).host === "example.com" && alert(0)

Fuzz results

Chrome logo
Chrome 144.0.0.0 desktop macOS 10.15.7

Updated

Fri Jan 23 2026
Found 1 result
Loading...
Firefox logo
Firefox 147.0 desktop macOS 10.15

Updated

Sun Jan 25 2026
Found 1 result
Loading...
Edge logo
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0

Updated

Mon Jan 26 2026
Found 1 result
Loading...
Safari logo
Safari 26.2 desktop macOS 10.15.7

Updated

Thu Jan 29 2026
Found 1 result
Loading...