Dereferencing request values before checking them

Dereferencing request values before checking them

Description

Accessing properties, calling methods or reading the length of a request value that may be missing can throw an exception.

Potential impact

  • An attacker may omit required parameters to trigger error responses. Depending on error handling and load, this may affect availability.
  • Error handling may expose internal state or exception details.

Remediation

  • Check request values before use with value != null, schema validation or appropriate defaults.
  • Declare required values in the validation layer and return a clear error when they are missing.

Examples

These are Express 5 route excerpts. In this version, res.send(number) returns the number as JSON.

Before

javascript
app.get("/length", (req, res) => {
  const id = req.query.id;
  res.send(id.length);
});

After

javascript
app.get("/length", (req, res) => {
  const id = req.query.id;
  if (id == null) {
    return res.status(400).end();
  }
  res.send(id.length);
});

Explanation:

  • Before: Reading a property or calling a method on a missing value such as req.query.id or req.body.name can throw an exception.
  • After: A missing value receives a 400 response before its length is read. A null check does not validate type or format; separately check the required string format and length.

References