Description
Accessing properties, calling methods or reading the length of a request value that may be missing can throw an exception.
Potential impact
- An attacker may omit required parameters to trigger error responses. Depending on error handling and load, this may affect availability.
- Error handling may expose internal state or exception details.
Remediation
- Check request values before use with
value != null, schema validation or appropriate defaults. - Declare required values in the validation layer and return a clear error when they are missing.
Examples
These are Express 5 route excerpts. In this version, res.send(number) returns the number as JSON.
Before
javascript
app.get("/length", (req, res) => {
const id = req.query.id;
res.send(id.length);
});
After
javascript
app.get("/length", (req, res) => {
const id = req.query.id;
if (id == null) {
return res.status(400).end();
}
res.send(id.length);
});
Explanation:
- Before: Reading a property or calling a method on a missing value such as
req.query.idorreq.body.namecan throw an exception. - After: A missing value receives a 400 response before its length is read. A null check does not validate type or format; separately check the required string format and length.