From 3cd17e6b85b306c2ab81b133bdeea042cdf266ea Mon Sep 17 00:00:00 2001 From: Norbert Biczo Date: Thu, 24 Sep 2026 14:00:48 +0200 Subject: [PATCH] fix: reject dot-segment path parameter values to prevent path traversal Path parameters with value "." or ".." are not encoded by the standard encoding functions (encodeURIComponent, requests.utils.quote, OkHttp addPathSegment, url.PathEscape) because dots are RFC 3986 unreserved characters. The downstream HTTP client then performs standard dot-segment normalisation, silently retargeting the request to a different resource than the caller intended. Add a validation guard that rejects any path parameter value that is exactly "." or ".." with a clear error message, in the same location and following the same pattern as the existing empty-value guards. Pre-encoding is not a viable workaround as it produces double-encoded values (%252E) which change the meaning of the parameter. Fixes: CWE-23 (Relative Path Traversal) / CWE-116 CVSS 3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8 Signed-off-by: Norbert Biczo