graphql-go / graphql-go/handler

Go ParseThru vulnerability

Open
#91 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
451
Forks
135
PR merge metrics
No merged PRs in 30d

Description

There is a vulnerability in Go url parsing. More on that here: https://www.oxeye.io/blog/golang-parameter-smuggling-attack

In a nutshell, the method Query() ignores the error produced by another function when finding a semicolon when parsing the query.
The solution is to replace usage of query = r.URL.Query() with query, err = url.ParseQuery(r.URL.RawQuery) to avoid ignoring the error produced by finding a semicolon when parsing the query.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.