False negative in go/email-injection for password reset links built from Forwarded / X-Forwarded-Host

未關閉
#21,770 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
45/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
冷清
技術堆疊
go
領域
security

研究方向

從 go/email-injection 開始,追蹤其 source-to-sink 流程如何處理透過自訂 struct、事件欄位和通知 helper 傳遞的值。將其與所描述的從 Forwarded/X-Forwarded-Host 到 password-reset-link 的路徑進行比較;完成的標準是查詢涵蓋間接流程,並避免報告中的 false negative。

由索引模型根據 Issue 內容生成。

描述

Hi team,

I think I found a false negative in go/email-injection.

I ran into this while looking at ZITADEL's CVE-2025-64101 / GHSA-mwmh-7px9-4c23. The vulnerable flow is:

  • host data comes from Forwarded / X-Forwarded-Host
  • it is stored in a request/domain context object
  • that value is later carried through an event / notification path
  • and eventually used to build a password reset link that gets emailed to the user

Very roughly, it looks like this:

hostFromHeader = r.Header.Get(header)

if host == "" {
    host = hostFromHeader
}

TriggeredAtOrigin: http.DomainContext(ctx).Origin()

url = login.InitPasswordLink(http_utils.DomainContext(ctx).Origin(), user.ID, code, user.ResourceOwner, authRequestID)

The upstream fix sanitizes the host before storing it in the domain context, so this seems like a real missed case, not just a noisy benchmark result.

My guess is that the source side is already covered well enough, since net/http.Request.Header is modeled as remote input. The gap seems to be later in the flow, once the value moves through custom structs / event fields / notification helpers before it becomes part of email content.

I think this pattern is fairly common in real Go code. Password reset and verification links are often built indirectly through app-specific context and mailer abstractions, not directly inside a modeled mail API call.

For comparison, Semgrep did flag this codebase, but only with a broader rule about request-derived origin/host usage. It was not precise, but the general idea may still be useful here: request-header-derived host/origin values that later become user-facing links in emails probably deserve better coverage.

A reasonable fix might be improving go/email-injection so flow is preserved better through custom carrier objects and “build link first, send email later” patterns.

主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 10 小時
30 天內合併 PR
134

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

github/codeql 的其他 Issue

查看 github/codeql 的全部 Issue

相似的 Issue

更多 Security Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。