Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

AuthTraceBleed

2026-09-23. Reported by GitHub CodeQL; sibling review and fixes by xet7. No CVE is assigned. CWE-1333, CWE-400, CWE-209 and CWE-497.

Scope

Saved CodeQL alerts #543 and #544 identify an unanchored OAuth-header regular expression and HTTP stack-trace disclosure in the loopback-only login integration fixture. That test provider is not a production identity service. Sibling review also found an HTTP stack-trace response in the shipped Sandstorm login adapter, active in Sandstorm mode.

Fix

The fixture bounds headers to 8 KiB, anchors individual parameter matches, rejects duplicate parameters and malformed percent encodings, and retains OAuth signature validation. The fixture and Sandstorm endpoint return fixed error text, without internal paths, stack traces or request-derived exception messages. This does not change successful authentication or authorize an unmatched Sandstorm token.

No Admin Panel Problems category is added: the fixture is outside the application, and removing exception details from generic Sandstorm failure responses does not distinguish attacks from operational failures.

Verification

Positive and negative tests exercise real signed HTTP requests, hostile headers, invalid signatures, malformed requests, Sandstorm success and failure, and tracked-source guards against direct HTTP stack sinks and the vulnerable OAuth scanner. A macOS ARM64 build and ten Chromium OAuth/Sandstorm checks pass, including valid signatures, rejected authorization and opaque failure responses. Hosted CodeQL has not been rerun.

Fix and regression coverage

Regression tests