Skip to content

Python: Model prefixmatch regular expression APIs - #22735

Open
tausbn wants to merge 1 commit into
mainfrom
tausbn/python315-model-prefixmatch
Open

tausbn wants to merge 1 commit into
mainfrom
tausbn/python315-model-prefixmatch

Conversation

@tausbn

@tausbn tausbn commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This has essentially the same security implications as the existing match, so we just extend the existing modelling to also handle prefixmatch.

This has essentially the same security implications as the existing
`match`, so we just extend the existing modelling to also handle
`prefixmatch`.
@tausbn
tausbn marked this pull request as ready for review October 2, 2026 12:44
@tausbn
tausbn requested a review from a team as a code owner October 2, 2026 12:44
Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The modeling consistently mirrors match and is covered across affected security and library behavior.

Review effort: Balanced
Findings: None

What changed in this PR

Extends Python regex modeling so Python 3.15’s prefixmatch is handled like match.

Changes:

  • Models direct and compiled prefixmatch calls, flags, match-object flow, and SSRF sanitization.
  • Adds coverage for regex injection, ReDoS, SSRF, and stdlib data flow.
  • Adds a change note and refreshed expected outputs.
File Description
python/​ql/​test/​query-tests/​Security/​CWE-918-ServerSideRequestForgery/​test_re_prefixmatch.py Adds SSRF tests.
python/​ql/​test/​query-tests/​Security/​CWE-918-ServerSideRequestForgery/​PartialServerSideRequestForgery.expected Updates partial SSRF expectations.
python/​ql/​test/​query-tests/​Security/​CWE-918-ServerSideRequestForgery/​FullServerSideRequestForgery.expected Updates full SSRF expectations.
python/​ql/​test/​query-tests/​Security/​CWE-730-RegexInjection/​RegexInjection.expected Updates regex-injection expectations.
python/​ql/​test/​query-tests/​Security/​CWE-730-RegexInjection/​re_prefixmatch.py Adds regex-injection cases.
python/​ql/​test/​query-tests/​Security/​CWE-730-PolynomialReDoS/​test.py Adds ReDoS cases.
python/​ql/​test/​query-tests/​Security/​CWE-730-PolynomialReDoS/​PolynomialReDoS.expected Updates ReDoS expectations.
python/​ql/​test/​query-tests/​Security/​CWE-730-PolynomialReDoS/​PolynomialBackTracking.expected Updates backtracking expectations.
python/​ql/​test/​library-tests/​regex/​test.py Tests prefixmatch flags.
python/​ql/​test/​library-tests/​regex/​Regex.expected Updates parsed-regex expectations.
python/​ql/​test/​library-tests/​regex/​Mode.expected Updates regex-mode expectations.
python/​ql/​test/​library-tests/​frameworks/​stdlib/​test_re_prefixmatch.py Tests stdlib taint summaries.
python/​ql/​lib/​semmle/​python/​security/​dataflow/​ServerSideRequestForgeryCustomizations.qll Recognizes successful prefixmatch validation.
python/​ql/​lib/​semmle/​python/​regexp/​internal/​ParseRegExp.qll Extracts direct-call flags.
python/​ql/​lib/​semmle/​python/​frameworks/​Stdlib.qll Models execution and match-object flow.
python/​ql/​lib/​change-notes/​2026-09-22-python315-prefixmatch.md Documents the analysis improvement.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants