Description
A hostname or domain validation pattern may accept unintended hosts if dots (.) are not escaped or the matching boundaries are incomplete.
Potential impact
- The defect may enable SSRF, open redirects or bypass of an external callback allow-list.
- An attacker may make an untrusted domain pass validation as a trusted one.
Remediation
- Escape domain separators as
\.in the regular expression. In a double-quoted Go string, write\\.. - Where possible, parse the URL and compare its host with an exact allow-list.
Examples
Before
go
ok, _ := regexp.MatchString("^api.example.com$", host)
After
go
ok, _ := regexp.MatchString("^api\\.example\\.com$", host)
Explanation:
- Before: Unescaped dots in hostname or domain patterns can admit a much wider set of inputs than the intended domain.
- After: In a Go interpreted string,
\\.passes\.to the regular expression to match a literal dot. Start and end anchors match the entire hostname.