Executive brief
srvx is a Node.js server framework component that routes HTTP requests and applies middleware such as authentication guards and rate limiters. Due to a URL parsing discrepancy, an attacker can craft a malicious HTTP request with a specially-formatted absolute URI to bypass route-based middleware protections, potentially gaining unauthorized access to protected endpoints. This requires direct network access to send raw HTTP requests, not possible through a web browser.
Technical details
The vulnerability is a pathname parsing discrepancy in srvx's FastURL parser (CWE-706: Use of Incorrectly-Resolved Name or Reference). When a raw HTTP request contains an absolute URI with a non-standard scheme (e.g., GET file://hehe?/internal/run HTTP/1.1), the FastURL manual parser incorrectly extracts the pathname as /internal/run, while the native URL parser would extract pathname as / with search ?/internal/run. This discrepancy allows an attacker to bypass middleware guards when a prior middleware triggers FastURL deoptimization (e.g., by accessing the hostname property), causing subsequent middleware to see a different pathname. The attack vector is network-based and requires sending a raw HTTP request, which cannot be performed from a browser. The fix (available in srvx 0.11.13) deopts FastURL to native URL for any string not starting with /, ensuring consistent pathname resolution across all middleware.
Affected products
- h3js srvx < 0.11.13
Timeline
- 2026-03-23: disclosed
- 2026-03-26: patched: srvx 0.11.13 released with fix