BUG: Uncaught TypeError Crash in CSRF Verification Middleware #31
Closed
opened 2026-05-22 15:40:02 +01:00 by Gandalf
·
1 comment
No Branch/Tag Specified
main
release/1.7.38
develop
release/1.7.37
release/1.7.36
release/1.7.35
release/1.7.34
release/1.7.33
release/1.7.32
release/1.7.31
release/1.7.30
release/1.7.29
release/1.7.28
release/1.7.27
release/1.7.26
release/1.7.25
release/1.7.24
release/1.7.23
release/1.7.22
release/1.7.21
release/1.7.20
release/1.7.19
release/1.7.18
release/1.7.17
release/1.7.16
release/1.7.15
release/1.7.14
release/1.7.13
release/1.7.12
release/1.7.11
release/1.7.10
release/1.7.9
release/1.7.8
release/1.7.7
release/1.7.6
release/1.7.5
release/1.7.4
release/1.7.3
release/1.6.0
release/1.5.5
release/1.5.3
release/1.5.2
release/1.5.0a
release/1.4.0
release/1.3.1a
release/1.3.1
release/1.3.0
release/v1.2.2
release/v1.2.1
release/v1.2.0
release/1.1.2
release/1.1.1
release/1.1.0
release/1.0.0
release/0.2.0
release/v0.1.5
release/0.1.4
release/0.1.3
release/0.1
v1.7.38
v1.7.37
v1.7.36
v1.7.35
v1.7.34
v1.7.33
v1.7.32
v1.7.31
v1.7.30
v1.7.29
v1.7.28
v1.7.27
v1.7.26
v1.7.25
v1.7.24
v1.7.23
v1.7.22
v1.7.21
v1.7.20
v1.7.19
v1.7.18
v1.7.17
v1.7.16
v1.7.15
v1.7.14
v1.7.13
v1.7.12
v1.7.11
v1.7.10
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.7.4
v1.7.3
v1.6.0
v1.5.5
v1.5.3
v1.5.2
v1.5.1
v1.5.0a
v1.4.0
v1.3.1a
v1.3.1
v1.2.2
v1.2.1
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.0
v0.2.0
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Labels
Clear labels
Area/Docker
Area/Download Clients
Area/Frontend
Area/History
Area/Logging
Area/Matching
Area/Proxy
Area/SSE
Area/Webhooks
Compat/Breaking
Compat/Non-Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Docker image and container packaging
Download client integrations
Client-side UI and build tooling
History and completed downloads views
Log streaming, file handling, and debug infrastructure
Matching and correlation logic
Upstream service proxy routes
Server-Sent Events and real-time streaming
Webhook processing and reliability
Breaking change that won't be backward compatible
Non-breaking compatibility change
Something is not working
Documentation changes
Improve existing functionality
New functionality
This is security issue
Issue or pull request related to testing
Priority
Critical
1
The priority is critical
Priority
High
2
The priority is high
Priority
Low
4
The priority is low
Priority
Medium
3
The priority is medium
Reviewed
Confirmed
1
Issue has been confirmed
Reviewed
Duplicate
2
This issue or pull request already exists
Reviewed
Invalid
3
Invalid issue
Reviewed
Won't Fix
3
This issue won't be fixed
Status
Abandoned
3
Somebody has started to work on this but abandoned work
Status
Blocked
1
Something is blocking this issue or pull request
Status
Need More Info
2
Feedback is required to reproduce issue or to continue work
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Gandalf/sofarr#31
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
verifyCsrf.js compares cookieToken.length !== headerToken.length at character-level. If multi-byte tokens are sent where string length matches but byte length differs, Buffer.from() yields differing lengths. Consequently, crypto.timingSafeEqual throws an unhandled TypeError crash (500) rather than a clean 403.
Resolution: Refactored server/middleware/verifyCsrf.js to instantiate byte buffers from tokens first, and then perform a timing-safe length verification on the buffers (a.length !== b.length) before running crypto.timingSafeEqual(). This prevents uncaught Node.js TypeErrors and handles multi-byte tokens gracefully. Added unit tests in tests/unit/verifyCsrf.test.js.