Bypassing incomplete regular-expression validation

Bypassing incomplete regular-expression validation

Description

A hostname or domain validation pattern may accept unintended hosts if dots (.) are not escaped or the matching boundaries are incomplete.

Potential impact

  • The defect may enable SSRF, open redirects or bypass of an external callback allow-list.
  • An attacker may make an untrusted domain pass validation as a trusted one.

Remediation

  • Escape domain separators as \. in the regular expression. In a double-quoted Go string, write \\..
  • Where possible, parse the URL and compare its host with an exact allow-list.

Examples

Before

go
ok, _ := regexp.MatchString("^api.example.com$", host)

After

go
ok, _ := regexp.MatchString("^api\\.example\\.com$", host)

Explanation:

  • Before: Unescaped dots in hostname or domain patterns can admit a much wider set of inputs than the intended domain.
  • After: In a Go interpreted string, \\. passes \. to the regular expression to match a literal dot. Start and end anchors match the entire hostname.

References