Skip to content

[tangentially related to CVE-2023-24329] urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters #99418

Description

@kenballus

Background

RFC 3986 defines a scheme like this:

  • scheme = ALPHA *( ALPHA / DIGIT / "+" / "-" / "." )

RFC 2234 defines an ALPHA like this:

  • ALPHA = %x41-5A / %x61-7A

The WHATWG URL spec defines a scheme like this:

The bug

This is the scheme string parsing code from Lib/urllib/parse.py:462-468:

    i = url.find(':')
    if i > 0:
        for c in url[:i]:
            if c not in scheme_chars:
                break
        else:
            scheme, url = url[:i].lower(), url[i+1:]

This is the definition of scheme_chars from Lib/urllib/parse.py:77-80:

scheme_chars = ('abcdefghijklmnopqrstuvwxyz'
                'ABCDEFGHIJKLMNOPQRSTUVWXYZ'
                '0123456789'
                '+-.')

This will erroneously validate schemes that begin with any of ('.', '-', '+', '0', '1', '2', '3', '4', '5', '6', '7', '8', '9'). This behavior is in violation of both specifications.

This bug is reproducible with the following snippet:

>>> from urllib.parse import urlparse
>>> urlparse(".://") # Should error, but doesn't
ParseResult(scheme='.', netloc='', path='', params='', query='', fragment='')

My environment

  • CPython versions tested on:
  • Operating system and architecture:
    • Arch Linux x86_64

Activity

  1. added
    stdlibStandard Library Python modules in the Lib/ directory
    on Nov 12, 2022
  2. added a commit that references this issue on Nov 13, 2022
  3. added 2 commits that reference this issue on Nov 13, 2022
  4. hauntsaninja commented on Nov 29, 2022

    @hauntsaninja
    Contributor

    Thanks, looks like this has been fixed

  5. vstinner commented on Apr 5, 2023

    @vstinner
    Member

    CVE-2023-24329 was assigned to this issue.

  6. changed the title [-]urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters[/-] [+][CVE-2023-24329] urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters[/+] on Apr 5, 2023
  7. vstinner commented on Apr 5, 2023

    @vstinner
    Member

    Python 3.7, 3.8 and 3.9 are affected by this issue and still get security fixes.

    @gpshead: Should this fix be backported to Python 3.7-3.9?

  8. vstinner commented on Apr 5, 2023

    @vstinner
    Member

    Ah, I don't see a fix for Python 3.10 neither, whereas the issue was reported on Python 3.10.

  9. vstinner commented on Apr 5, 2023

    @vstinner
    Member
  10. gpshead commented on Apr 8, 2023

    @gpshead
    Member

    Please see #102153..

  11. gpshead commented on Apr 8, 2023

    @gpshead
    Member

    (ie: that python-security urlparse-scheme blog text is currently wrong: this is not fixed, and the first report was in July, not November)

  12. vstinner commented on May 4, 2023

    @vstinner
    Member

    (ie: that python-security urlparse-scheme blog text is currently wrong: this is not fixed, and the first report was in July, not November)

    I'm maintaining this page manually and it's quite a lot of work to maintain it. I tried to automate as many things as possible. The source can be found in the YAML file: https://github.com/vstinner/python-security/blob/main/vulnerabilities.yaml#L2134

    Free free to propose a PR to fix the entry ;-)

  13. ngie-eign commented on May 20, 2023

    @ngie-eign
    Contributor

    The fix for this CVE should really be backported if applicable.

  14. changed the title [-][CVE-2023-24329] urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters[/-] [+][tangentially related to CVE-2023-24329] urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters[/+] on May 20, 2023
  15. gpshead commented on May 20, 2023

    @gpshead
    Member

    The fix for this CVE should really be backported if applicable.

    This issue does not contain the fix.

    See #102153.

  16. ngie-eign commented on May 20, 2023

    @ngie-eign
    Contributor

    The fix for this CVE should really be backported if applicable.

    This issue does not contain the fix.

    See #102153.

    @gpshead : thank you so very much for the pointer! I'll do some poking around next week to see if some other OS distributions have addressed this and if there aren't any available fixes, try crafting (an) appropriate patch(es) and link it/them to the appropriate issue.

    I work on a project that uses 3.8; if it's too much work for 3.7, I'll just look into making the 3.8 patch work.

  17. added 2 commits that reference this issue on May 21, 2024
  18. added 2 commits that reference this issue on Sep 19, 2024
  19. added a commit that references this issue on Jul 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    stdlibStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions