Skip to content

fix: ACL bypass via prefix topic matching (CVSS 4.3) - #169

Merged
wind-c merged 1 commit into
mainfrom
fix/acl-prefix-topic-bypass
Jul 12, 2026
Merged

wind-c merged 1 commit into
mainfrom
fix/acl-prefix-topic-bypass

Conversation

@wind-c

@wind-c wind-c commented Jul 12, 2026

Copy link
Copy Markdown
Owner

Fixes an ACL bypass vulnerability (CVSS 3.1 4.3) reported by Team Atlanta. A literal write ACL like 'allowed' was treated as matching a publish to 'allowed/secret', allowing low-privilege clients to publish to protected child topics.

Root cause: MatchTopic at ledger.go:162 returns true unconditionally after exhausting filter parts, without checking whether topic parts remain.

Fix: return elements, len(topicParts) == len(filterParts). The '#' multi-level wildcard path is unaffected (returns early).

/cc @wind-c

A literal ACL filter like 'allowed' was treated as matching publish
to 'allowed/secret'. MatchTopic returned true after exhausting filter
parts without checking whether topic parts remained.

Fix: return matched only when len(topicParts) == len(filterParts).
The '#' wildcard path already handles multi-level matches correctly.

Reported by Team Atlanta.
@wind-c
wind-c merged commit 7cee248 into main Jul 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant