Evidenceufo-158
Unexpected behavior when passing a `data:` URL into parseURL()
ufo#158, at commit 2caeb30. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
RIGHT_FAILUREexecuted against the upstream checkout.
- Outcome
- PATCH_REJECTED
- Wall time
- 122.4s
- Checks
- 5 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
Unexpected behavior when passing a `data:` URL into parseURL()
### Environment
Version: 1.2.0
### Reproduction
https://stackblitz.com/edit/js-smsxy5?file=index.js
```js
parseURL('data:image/png;base64,aaa//bbbbbb/ccc')
// { auth: "", hash: "", host: "bbbbbb", pathname: "/ccc", protocol: "", search: "" }
```
### Describe the bug
When a data URL is passed into `parseURL()` it might detect a host and a pathname based on the base64 content of the data URL.
### Additional context
Downstream issue: https://github.com/unjs/nitro/issues/1431
### Logs
_No response_- Repository
- unjs/ufo
- Issue
- #158
- Commit
- 2caeb30971a4e1affa281c30f7261b74deeb53a5
- Why this commit
- The first parent of the fix commit 3bfbf5ac78085db4d7513fe96900dcce13776226, which GitHub binds to this issue via CLOSED_EVENT_PR. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- parseURL('data:image/png;base64,aaa//bbbbbb/ccc') produces { auth: '', hash: '', host: 'bbbbbb', pathname: '/ccc', protocol: '', search: '' }; the fix makes it produce { auth: '', hash: '', host: '', href: 'data:image/png;base64,aaa//bbbbbb/ccc', pathname: 'image/png;base64,aaa//bbbbbb/ccc', protocol: 'data:', search: '' }.
- Expression
- parseURL('data:image/png;base64,aaa//bbbbbb/ccc')
- Reported output
- { auth: "", hash: "", host: "bbbbbb", pathname: "/ccc", protocol: "", search: "" }
- Where that came from
- Read mechanically from the report's fenced code, NEXT_LINE form: `parseURL('data:image/png;base64,aaa//bbbbbb/ccc') // { auth: "", hash: "", host: "bbbbbb", pathname: "/ccc", protocol: "", search: "" }`.
03What happened
The live run reproduced the reported failure.
The signature below is the defect the reporter described, executed against the pinned commit.
`parseURL('data:image/png;base64,aaa//bbbbbb/ccc')` still produces { auth: "", hash: "", host: "bbbbbb", pathname: "/ccc", protocol: "", search: "" } (read {
protocol: '',
auth: '',
host: 'bbbbbb',
pathname: '/ccc',
search: '',
hash: ''
})The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `parseURL('data:image/png;base64,aaa//bbbbbb/ccc')` still produces { auth: "", hash: "", host: "bbbbbb", pathname: "/ccc", protocol: "", search: "" } (read { protocol: '', auth: '', host: 'bbbbbb', pathname: '/ccc', search: '', hash: '' }) |
| right-failure | pass | Reproduced the reported failure: parseURL('data:image/png;base64,aaa//bbbbbb/ccc') produces { auth: '', hash: '', host: 'bbbbbb', pathname: '/ccc', protocol: '', search: '' }; the fix makes it produce { auth: '', hash: '', host: '', href: 'data:image/png;base64,aaa//bbbbbb/ccc', pathname: 'image/png;base64,aaa//bbbbbb/ccc', protocol: 'data:', search: '' }. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 2caeb30, run the report through the CLI the way the study did.
git clone https://github.com/unjs/ufo git checkout 2caeb30971a4e1affa281c30f7261b74deeb53a5 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color