`urllib.parse` accepts invalid characters in IPv6 ZoneIDs and IPvFuture addresses
還沒有人認領這個 Issue。
- 主要語言
- Python
- 星號
- 77.2k
- 分支
- 36k
- PR 合併指標
- PR 指標待擷取
描述
Bug report
Bug description:
Issue Summary
The urllib.parse module currently allows invalid characters in both IPv6 Zone Identifiers and IPvFuture addresses due to discrepancies between how it validates these components and what is defined in relevant RFCs.
Details
-
IPv6 ZoneID Parsing
-
According to RFC 6874, the IPv6 ZoneID should follow a restricted format when used in a URL. Specifically, it must use percent-encoding (
%followed by two hex digits) for non-allowed characters, and only the following characters are permitted in the decoded form:ALPHA / DIGIT / "-" / "." / "_" / "~" -
However,
urllib.parserelies on theipaddressmodule to parse ZoneIDs, which follows the broader rules from RFC 4007, accepting any non-null string. -
This results in invalid ZoneIDs being accepted in parsed URLs, which could cause compatibility issues or security concerns in strict RFC-compliant applications.
-
-
IPvFuture Parsing
-
RFC 3986 defines the format of an
IPvFutureaddress as:"v" 1*HEXDIG "." 1*( unreserved / sub-delims / ":" )where:
unreserved= ALPHA / DIGIT / "-" / "." / "_" / "~"sub-delims= "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" / "," / ";" / "="
-
However, the current regex used by
urllib.parsefor validatingIPvFutureuses a.+pattern, which matches any character sequence. This allows completely invalid strings (including those with spaces or other illegal characters) to be accepted as valid IPvFuture addresses.
-
Expected Behavior
-
urllib.parseshould:- Enforce the character restrictions for ZoneIDs as defined in RFC 6874 when parsing URL hosts.
- Strictly validate IPvFuture addresses based on the character classes defined in RFC 3986.
Actual Behavior
- Invalid characters are accepted in both ZoneIDs and IPvFuture segments.
Suggested Fix
-
Update
urllib.parse:- To decode and validate ZoneID characters according to RFC 6874.
- To adjust the regex or parsing logic for IPvFuture addresses to comply with the ABNF in RFC 3986.
Example
from urllib.parse import urlparse
# Invalid ZoneID containing `@`
url = urlparse("http://[fe80::1%en0@]:8080")
print(url.hostname) # Should raise or reject invalid ZoneID
# Invalid IPvFuture containing ` ` (space)
url = urlparse("http://[v1.invalid space]/")
print(url.hostname) # Should raise or reject invalid IPvFuture
Impact
This behavior may lead to security vulnerabilities or unexpected behavior in applications that rely on urllib.parse for URL validation or sanitization based on RFC compliance.
In particular:
-
A developer may incorrectly assume that
urllib.parseenforces RFC 3986, RFC 6874, or RFC 4007 character restrictions. -
If the parser accepts invalid ZoneIDs or malformed IPvFuture components, applications could:
- Accept and process invalid or malicious URLs.
- Misroute requests, leading to access control issues.
- Be exposed to injection attacks (e.g., if the ZoneID is reused unsanitized in shell commands or logging).
- Fail silently in contexts where strict compliance is expected, introducing logic bugs or interoperability issues.
Example scenario:
If a developer trusts urllib.parse to reject invalid hostnames, and then interpolates the parsed url.hostname or url.netloc into system commands, code (HTML, python, javascript, etc...), logs quoted values, or CSV/JSON/XML data, an attacker could exploit improperly validated input.
Recommendation:
Until this behavior is corrected, developers should not rely solely on urllib.parse for validation of ZoneIDs or IPvFuture addresses, and should consider adding additional sanitization layers when handling user-supplied URLs.
CPython versions tested on:
3.13
Operating systems tested on:
Linux
Linked PRs
- gh-137147
- gh-137148
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
研究方向
從 issue 中描述的 urllib.parse 主機驗證開始,並將其對 ZoneID 和 IPvFuture 的處理與 RFC 6874 和 RFC 3986 進行比較。為無效字元範例新增覆蓋,並驗證兩種形式都會被拒絕,同時有效形式仍會被接受。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- python
- 領域
- networking
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 停滯
- 描述清晰度
- 描述清楚
- 新手友好度
- 25/100