".://" is a particularly egregious example. (and, by the same principle, "evil.com://good.com")
- Python 3.6's urllib.parse sees the "." as the URL's scheme, and an empty authority.
- Python 3.11's urllib.parse sees the entire ".://" as the URL's path.
- urllib3.util.parse_urlsees the "." as the URL's hostname, the ":" as the separator for an empty port number, and the "//" as the path. (this is one of the most downloaded packages on PyPI)
- Boost::URL rejects the URL outright.
If you're going by RFC 3986, then only Boost::URL is exhibiting the correct behavior. If you're going by the WHATWG URL standard, then I don't know which one of these behaviors (if any) is correct.
If you're interested in collaborating on this project, please send me email. My address is in the footer at https://kallus.org