Commit ada3c6b
fix: block open redirect via encoded backslash (%5C) in nginx (#2354)
## Summary
- Block requests containing encoded backslash (`%5C`) in the URI to
prevent an open redirect vulnerability
- The nginx trailing slash removal rule (`rewrite ^(.+)/$ $1 redirect`)
can produce redirects that browsers misinterpret when the URI contains
`%5C` - some browsers decode it to `\`, normalize to `/`, and create
protocol-relative navigation
- Fix adds a server-level check on `$request_uri` that returns 400
before any rewrite processing
Fixes apify/apify-core#26551
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 8214e69 commit ada3c6b
2 files changed
Lines changed: 23 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
78 | 94 | | |
79 | 95 | | |
80 | 96 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
24 | 31 | | |
25 | 32 | | |
26 | 33 | | |
| |||
0 commit comments