Skip to content

[Aikido] Fix date-prefix route normalization bypass in build_route_from_url - #742

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137918509-m2wf
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137918509-m2wf

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a route normalization bypass vulnerability in the build_route_from_url helper where URL segments with date prefixes followed by additional characters (e.g., "2024-01-01-export") were incorrectly normalized to :date parameters, allowing attackers to bypass exact endpoint policies. The fix properly anchors the DATE_REGEX pattern with word boundaries to match only complete date segments, ensuring that only pure date formats are normalized. The changes were made to aikido_zen/helpers/build_route_from_url.py and validated with additional test cases in aikido_zen/helpers/build_route_from_url_test.py.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811707770
HIGH
build_route_from_url() classifies URL segments with DATE_REGEX.match(). The first alternative in DATE_REGEX is anchored only at the beginning, so a segment beginning with an ISO date and containing a suffix is classified as a date and replaced with :date. The normalized route is then used as the endpoint-policy lookup key. For an exact policy configured for /internal/2024-01-01-export, a request to that path is normalized to /internal/:date, so the exact endpoint is not selected. When no applicable wildcard endpoint matches, ip_allowed_to_access_route() allows the request because its endpoint list is empty, and should_block_request() does not select endpoint-specific rate limiting because it likewise requires a non-empty match. The primary defect is the lossy date classification; failing closed on an unexpected policy miss would be useful defense in depth.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant