Query

Many fetch sinks take their target from a query parameter: ?url=, ?target=, ?image=, ?next=. The validation usually runs once, on the string in that parameter, and then the request is issued. The two pages here break the assumption that passing validation once means the final request is safe.

  • Redirect-based bypass: the submitted URL points at a host the allowlist permits, but that host responds with a redirect to an internal target. A client that follows redirects validates the first URL and connects to the second.
  • Parameter pollution: supplying the parameter twice (?url=allowed&url=internal) exploits a mismatch between the component that validates and the component that fetches, when they disagree on which occurrence wins.

Both live at the query layer because they manipulate how the parameter is parsed and followed, not how the host or path is written. They frequently combine with the Authority tricks: the final, post-redirect or post-pollution target is still an internal host written with one of those encodings.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more