blob: c41b6da06eb8ae8fe613debd6733db1246742934 [file] [edit]
{
"schema_version": "1.3.1",
"id": "GO-2026-4950",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"summary": "Authorization bypass via double-encoded paths in github.com/valyala/fasthttp",
"details": "In github.com/valyala/fasthttp before 1.70.0, ServeFile and ServeFS reinterpret filesystem paths as URIs, decoding percent-encoded sequences and treating characters like '?' and '#' as URI delimiters. In applications where authorization guards inspect ctx.Path() before passing paths to file-serving handlers, double-encoded path variants (e.g., /%2561dmin/export.csv) bypass access controls while still resolving to the protected file on disk.",
"affected": [
{
"package": {
"name": "github.com/valyala/fasthttp",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.70.0"
}
]
}
],
"ecosystem_specific": {
"imports": [
{
"path": "github.com/valyala/fasthttp",
"symbols": [
"RequestCtx.SendFile",
"RequestCtx.SendFileBytes",
"ServeFS",
"ServeFile",
"ServeFileBytes",
"ServeFileBytesUncompressed",
"ServeFileUncompressed"
]
}
]
}
}
],
"references": [
{
"type": "REPORT",
"url": "https://github.com/golang/vulndb/issues/4950"
},
{
"type": "FIX",
"url": "https://github.com/valyala/fasthttp/pull/2163"
},
{
"type": "WEB",
"url": "https://gist.github.com/thesmartshadow/af53acdfe0d6ce352d14eb86cecf5a08"
},
{
"type": "WEB",
"url": "https://github.com/valyala/fasthttp/releases/tag/v1.70.0"
}
],
"credits": [
{
"name": "Ali Firas (thesmartshadow)"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2026-4950",
"review_status": "REVIEWED"
}
}