Skip to content

Commit a438682

Browse files
sethmlarsonZeroIntensity
authored andcommitted
[CVE-2025-0938] disallow square brackets ([ and ]) in domain names for parsed URLs
* Use Sphinx references Co-authored-by: Peter Bierma <[email protected]> * Add mismatched bracket test cases, fix news format * Add more test coverage for ports Fixes: bsc#1236705 (CVE-2025-0938) Fixes: gh#python#105704 From-PR: gh#python/cpython!129418 Co-authored-by: Seth Michael Larson <[email protected]> Co-authored-by: Peter Bierma <[email protected]> Patch: CVE-2025-0938-sq-brackets-domain-names.patch
1 parent 4f2496b commit a438682

File tree

3 files changed

+58
-3
lines changed

3 files changed

+58
-3
lines changed

Lib/test/test_urlparse.py

Lines changed: 36 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1046,16 +1046,51 @@ def test_invalid_bracketed_hosts(self):
10461046
self.assertRaises(ValueError, urllib.parse.urlsplit, 'Scheme://user@[0439:23af::2309::fae7:1234]/Path?Query')
10471047
self.assertRaises(ValueError, urllib.parse.urlsplit, 'Scheme://user@[0439:23af:2309::fae7:1234:2342:438e:192.0.2.146]/Path?Query')
10481048
self.assertRaises(ValueError, urllib.parse.urlsplit, 'Scheme://user@]v6a.ip[/Path')
1049+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip]')
1050+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip].suffix')
1051+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip]/')
1052+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip].suffix/')
1053+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip]?')
1054+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip].suffix?')
1055+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]')
1056+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix')
1057+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]/')
1058+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix/')
1059+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]?')
1060+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix?')
1061+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:a')
1062+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:a')
1063+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:a1')
1064+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:a1')
1065+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:1a')
1066+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:1a')
1067+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:')
1068+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[::1].suffix:/')
1069+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[::1]:?')
1070+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://user@prefix.[v6a.ip]')
1071+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://user@[v6a.ip].suffix')
1072+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://[v6a.ip')
1073+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip]')
1074+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://]v6a.ip[')
1075+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://]v6a.ip')
1076+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip[')
1077+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix.[v6a.ip')
1078+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip].suffix')
1079+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix]v6a.ip[suffix')
1080+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://prefix]v6a.ip')
1081+
self.assertRaises(ValueError, urllib.parse.urlsplit, 'scheme://v6a.ip[suffix')
10491082

10501083
def test_splitting_bracketed_hosts(self):
1051-
p1 = urllib.parse.urlsplit('scheme://user@[v6a.ip]/path?query')
1084+
p1 = urllib.parse.urlsplit('scheme://user@[v6a.ip]:1234/path?query')
10521085
self.assertEqual(p1.hostname, 'v6a.ip')
10531086
self.assertEqual(p1.username, 'user')
10541087
self.assertEqual(p1.path, '/path')
1088+
self.assertEqual(p1.port, 1234)
10551089
p2 = urllib.parse.urlsplit('scheme://user@[0439:23af:2309::fae7%test]/path?query')
10561090
self.assertEqual(p2.hostname, '0439:23af:2309::fae7%test')
10571091
self.assertEqual(p2.username, 'user')
10581092
self.assertEqual(p2.path, '/path')
1093+
self.assertIs(p2.port, None)
10591094
p3 = urllib.parse.urlsplit('scheme://user@[0439:23af:2309::fae7:1234:192.0.2.146%test]/path?query')
10601095
self.assertEqual(p3.hostname, '0439:23af:2309::fae7:1234:192.0.2.146%test')
10611096
self.assertEqual(p3.username, 'user')

Lib/urllib/parse.py

Lines changed: 18 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -418,6 +418,23 @@ def _checknetloc(netloc):
418418
raise ValueError("netloc '" + netloc + "' contains invalid " +
419419
"characters under NFKC normalization")
420420

421+
def _check_bracketed_netloc(netloc):
422+
# Note that this function must mirror the splitting
423+
# done in NetlocResultMixins._hostinfo().
424+
hostname_and_port = netloc.rpartition('@')[2]
425+
before_bracket, have_open_br, bracketed = hostname_and_port.partition('[')
426+
if have_open_br:
427+
# No data is allowed before a bracket.
428+
if before_bracket:
429+
raise ValueError("Invalid IPv6 URL")
430+
hostname, _, port = bracketed.partition(']')
431+
# No data is allowed after the bracket but before the port delimiter.
432+
if port and not port.startswith(":"):
433+
raise ValueError("Invalid IPv6 URL")
434+
else:
435+
hostname, _, port = hostname_and_port.partition(':')
436+
_check_bracketed_host(hostname)
437+
421438
# Valid bracketed hosts are defined in
422439
# https://www.rfc-editor.org/rfc/rfc3986#page-49 and https://url.spec.whatwg.org/
423440
def _check_bracketed_host(hostname):
@@ -485,8 +502,7 @@ def urlsplit(url, scheme='', allow_fragments=True):
485502
(']' in netloc and '[' not in netloc)):
486503
raise ValueError("Invalid IPv6 URL")
487504
if '[' in netloc and ']' in netloc:
488-
bracketed_host = netloc.partition('[')[2].partition(']')[0]
489-
_check_bracketed_host(bracketed_host)
505+
_check_bracketed_netloc(netloc)
490506
if allow_fragments and '#' in url:
491507
url, fragment = url.split('#', 1)
492508
if '?' in url:
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
When using :func:`urllib.parse.urlsplit` and :func:`urllib.parse.urlparse` host
2+
parsing would not reject domain names containing square brackets (``[`` and
3+
``]``). Square brackets are only valid for IPv6 and IPvFuture hosts according to
4+
`RFC 3986 Section 3.2.2 <https://www.rfc-editor.org/rfc/rfc3986#section-3.2.2>`__.

0 commit comments

Comments
 (0)