Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2024-0004·information-disclosure

Improper error handling in parameters url, w, and q (unauthenticated and wallet-connected)

Acknowledgedpentestblackboxnextjs
TL;DR

Malformed values supplied via url, w, and q surfaced specific Next.js error strings ('q parameter must be a number between 1 and 100', 'requested resource isn't a valid image', and similar) that leaked implementation details to anyone probing the surface.

Severity
MEDIUM
Impact
MEDIUM
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description

Description

Malformed values supplied via the url, w, and q parameters returned specific error strings disclosing internal validation rules and framework details:

"q" parameter (quality) must be a number between 1 and 100 "w" parameter (width) of 6400 is not allowed The requested resource isn't a valid image.

These messages disclose internal validation rules and framework details that accelerate reconnaissance for follow-on probing.

03Section · Impact

Impact

Information disclosure. Lowers the cost for an attacker to map the validation surface and craft follow-on payloads.

04Section · Recommendation

Recommendation

Normalize all validation error responses to a single safe schema (generic message, no field-specific internals leaked). Catch unexpected exceptions globally and return a controlled 4xx/5xx with no leakage. Log full traces server-side, not in client responses.

Dedprz: Acknowledged. Zealynx: Acknowledged.

F-2024-0004