Exploiting URL Parsing Confusion
ID: 1da31a80-7fab-5217-9205-6375a7e77fc7
STIX ID: report--1da31a80-7fab-5217-9205-6375a7e77fc7
Feed Name: Claroty Team82
Team82 and Snyk analyzed 16 URL parsing libraries and identified five classes of parsing inconsistencies (scheme confusion, slashes confusion, backslash confusion, URL-encoded data confusion, and scheme mixup) that attackers can abuse to cause SSRF, information leaks, open-redirects, denial-of-service, and potentially remote code execution. The research uncovered eight vulnerabilities across multiple languages and frameworks (listed with CVEs), includes real-world bypass examples (e.g., a Log4j JNDI bypass using URL parsing differences), and provides recommendations and a detailed paper documenting findings and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
