Skip to content

Commit 2082bab

Browse files
sethmlarsonZeroIntensity
authored andcommitted
00450: CVE-2025-0938: Disallow square brackets ([ and ]) in domain names for parsed URLs
Co-authored-by: Peter Bierma <[email protected]>
1 parent b281281 commit 2082bab

File tree

3 files changed

+58
-3
lines changed

3 files changed

+58
-3
lines changed

Lib/test/test_urlparse.py

Lines changed: 36 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1087,16 +1087,51 @@ def test_invalid_bracketed_hosts(self):
10871087
self.assertRaises(ValueError, urllib.parse.urlsplit, 'Scheme://user@[0439:23af::2309::fae7:1234]/Path?Query')
10881088
self.assertRaises(ValueError, urllib.parse.urlsplit, 'Scheme://user@[0439:23af:2309::fae7:1234:2342:438e:192.0.2.146]/Path?Query')
10891089
self.assertRaises(ValueError, urllib.parse.urlsplit, 'Scheme://user@]v6a.ip[/Path')
1090+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip]')
1091+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip].suffix')
1092+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip]/')
1093+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip].suffix/')
1094+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip]?')
1095+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip].suffix?')
1096+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]')
1097+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix')
1098+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]/')
1099+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix/')
1100+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]?')
1101+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix?')
1102+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:a')
1103+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:a')
1104+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:a1')
1105+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:a1')
1106+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:1a')
1107+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:1a')
1108+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:')
1109+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:/')
1110+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:?')
1111+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://user@prefix.[v6a.ip]')
1112+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://user@[v6a.ip].suffix')
1113+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip')
1114+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip]')
1115+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://]v6a.ip[')
1116+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://]v6a.ip')
1117+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip[')
1118+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip')
1119+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip].suffix')
1120+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix]v6a.ip[suffix')
1121+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix]v6a.ip')
1122+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip[suffix')
10901123

10911124
def test_splitting_bracketed_hosts(self):
1092-
p1 = urllib.parse.urlsplit('scheme://user@[v6a.ip]/path?query')
1125+
p1 = urllib.parse.urlsplit('scheme://user@[v6a.ip]:1234/path?query')
10931126
self.assertEqual(p1.hostname, 'v6a.ip')
10941127
self.assertEqual(p1.username, 'user')
10951128
self.assertEqual(p1.path, '/path')
1129+
self.assertEqual(p1.port, 1234)
10961130
p2 = urllib.parse.urlsplit('scheme://user@[0439:23af:2309::fae7]/path?query')
10971131
self.assertEqual(p2.hostname, '0439:23af:2309::fae7')
10981132
self.assertEqual(p2.username, 'user')
10991133
self.assertEqual(p2.path, '/path')
1134+
self.assertIs(p2.port, None)
11001135
p3 = urllib.parse.urlsplit('scheme://user@[0439:23af:2309::fae7:1234:192.0.2.146]/path?query')
11011136
self.assertEqual(p3.hostname, '0439:23af:2309::fae7:1234:192.0.2.146')
11021137
self.assertEqual(p3.username, 'user')

Lib/urllib/parse.py

Lines changed: 18 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -426,6 +426,23 @@ def _remove_unsafe_bytes_from_url(url):
426426
url = url.replace(b, "")
427427
return url
428428

429+
def _check_bracketed_netloc(netloc):
430+
# Note that this function must mirror the splitting
431+
# done in NetlocResultMixins._hostinfo().
432+
hostname_and_port = netloc.rpartition('@')[2]
433+
before_bracket, have_open_br, bracketed = hostname_and_port.partition('[')
434+
if have_open_br:
435+
# No data is allowed before a bracket.
436+
if before_bracket:
437+
raise ValueError("Invalid IPv6 URL")
438+
hostname, _, port = bracketed.partition(']')
439+
# No data is allowed after the bracket but before the port delimiter.
440+
if port and not port.startswith(":"):
441+
raise ValueError("Invalid IPv6 URL")
442+
else:
443+
hostname, _, port = hostname_and_port.partition(':')
444+
_check_bracketed_host(hostname)
445+
429446
# Valid bracketed hosts are defined in
430447
# https://www.rfc-editor.org/rfc/rfc3986#page-49 and https://url.spec.whatwg.org/
431448
def _check_bracketed_host(hostname):
@@ -493,8 +510,7 @@ def urlsplit(url, scheme='', allow_fragments=True):
493510
(']' in netloc and '[' not in netloc)):
494511
raise ValueError("Invalid IPv6 URL")
495512
if '[' in netloc and ']' in netloc:
496-
bracketed_host = netloc.partition('[')[2].partition(']')[0]
497-
_check_bracketed_host(bracketed_host)
513+
_check_bracketed_netloc(netloc)
498514
if allow_fragments and '#' in url:
499515
url, fragment = url.split('#', 1)
500516
if '?' in url:
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
When using :func:`urllib.parse.urlsplit` and :func:`urllib.parse.urlparse` host
2+
parsing would not reject domain names containing square brackets (``[`` and
3+
``]``). Square brackets are only valid for IPv6 and IPvFuture hosts according to
4+
`RFC 3986 Section 3.2.2 <https://www.rfc-editor.org/rfc/rfc3986#section-3.2.2>`__.

0 commit comments

Comments
 (0)