Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

java/ssrf: allowlist guard not recognized when expressed via Stream/lambda (anyMatch), only via plain equals()/for-loop

未关闭
#22,259 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
45/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
java
领域
devtools, security

调研方向

从 java/ssrf 查询以及它使用的共享 sanitizer-guard 库开始;检查现有的 equals() 和循环形式是如何建模的。为 Arrays.stream(...).anyMatch(...)、method-reference 和 contains(...) 示例添加回归覆盖,并验证已识别的 allowlist 检查会清除 SSRF 警报,同时不会削弱其他情况。

由索引模型根据 Issue 内容生成。

描述

Query

java/ssrf (Server-side request forgery), Java/Kotlin Security/CWE-918

Summary

The SSRF sanitizer-guard recognition for this query does not appear to model an allowlist check expressed via Arrays.stream(...).anyMatch(...) (or other Stream/lambda/method-reference based equality checks) as taint-clearing, even though a functionally identical check written as a plain for loop with .equals()/.equalsIgnoreCase() calls is recognized and clears the alert.

Example (not recognized — alert fires)
private static boolean isAllowedHost(String host, String... allowedHosts) {
    return Arrays.stream(allowedHosts).anyMatch(host::equalsIgnoreCase);
}

void fetch(String userUrl) {
    URI uri = new URI(userUrl);
    if (isAllowedHost(uri.getHost(), "example.com")) {
        uri.toURL().openConnection(); // still flagged as SSRF sink
    }
}
Example (recognized — alert clears)
private static boolean isAllowedHost(String host, String... allowedHosts) {
    for (String allowed : allowedHosts) {
        if (allowed.equalsIgnoreCase(host)) {
            return true;
        }
    }
    return false;
}

(Identical behavior/contract; only the loop construct differs.)

Why this matters

Lambda-based and Stream-based collection idioms (anyMatch, Set.of(...).contains(...), etc.) have been idiomatic, widely-used Java since Java 8 (2014). A sanitizer-guard recognizer that only matches a narrow inline if (LITERAL.equals(x))/plain-loop shape — and not equivalent Stream/lambda forms — produces false positives that push teams toward less readable, less idiomatic code purely to satisfy the analyzer, with no corresponding security benefit. This also seems inconsistent with sanitizer/guard modeling in other CodeQL queries that do recognize Collection.contains(...)-style checks.

Ask

Could the java/ssrf (and ideally the shared sanitizer-guard library used across similar taint-tracking queries) be extended to recognize equality-based allowlist checks expressed via common Stream/lambda idioms (Arrays.stream(...).anyMatch(x::equals), Collection.contains(x), Set.of(...).contains(x)) as taint-clearing guards, equivalent to their imperative-loop counterparts?

Happy to provide a minimal reproducible test case/repo if useful.

主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 16 小时
30 天内合并 PR
143

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/codeql 的其他 Issue

查看 github/codeql 的全部 Issue

相似的 Issue

更多 DevTools Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。