SA is inventing URIs
Alex <[email protected]> Sat, 20 Jun 2026 17:08:44 -0400
| Newsgroups | gmane.mail.spam.spamassassin.general |
|---|---|
| Message-ID | <CAB1R3sgrfZM+emm5ueBE5ZmWxE0hBrTHpYAdDTfu4hX5XSgB6w@mail.gmail.com> |
--00000000000033fbf50654b5d157 Content-Type: text/plain; charset="UTF-8" SpamAssassin 4.0.3 appears to incorrectly promote a URL query parameter value into a standalone URI hostname and then performs URIDNSBL lookups against the generated domain. Observed behavior: Input message contains only the following URI: https://substack.com/signup?r=to8ex Debug output shows SpamAssassin correctly parsing the original URI: Jun 20 17:04:48.788 dbg: uri: canonicalizing parsed uri: https://substack.com/signup?r=to8ex Jun 20 17:04:48.788 dbg: uri: cleaned uri: https://substack.com/signup?r=to8ex Jun 20 17:04:48.788 dbg: uri: added host: substack.com domain: substack.com Immediately afterward, SpamAssassin creates a second URI which does not exist in the message: Jun 20 17:04:48.821 dbg: uri: canonicalizing parsed uri: http://to8ex Jun 20 17:04:48.822 dbg: uri: cleaned uri: http://to8ex Jun 20 17:04:48.822 dbg: uri: cleaned uri: http://www.to8ex.com Jun 20 17:04:48.822 dbg: uri: added host: www.to8ex.com domain: to8ex.com SpamAssassin then performs URIDNSBL lookups against the generated domain: Jun 20 17:04:48.836 dbg: uridnsbl: considering host=www.to8ex.com, domain=to8ex.com Expected behavior: The query parameter value "to8ex" should remain data associated with the URI: https://substack.com/signup?r=to8ex No standalone hostname or domain should be generated from the parameter value. --00000000000033fbf50654b5d157 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><pre class=3D"gmail-overflow-visible! gmail-px-0!"><div cl= ass=3D"gmail-relative gmail-w-full gmail-mt-4 gmail-mb-1"><div class=3D"gma= il-"><div class=3D"gmail-contents"><div class=3D"gmail-relative"><div class= =3D"gmail-h-full gmail-min-h-0 gmail-min-w-0"><div class=3D"gmail-h-full gm= ail-min-h-0 gmail-min-w-0"><div class=3D"gmail-border gmail-border-token-bo= rder-light gmail-border-radius-3xl gmail-corner-superellipse/1.1 gmail-roun= ded-3xl"><div class=3D"gmail-h-full gmail-w-full gmail-border-radius-3xl gm= ail-bg-token-bg-elevated-secondary gmail-corner-superellipse/1.1 gmail-over= flow-clip gmail-rounded-3xl gmail-lxnfua_clipPathFallback"><div class=3D"gm= ail-relative"><div class=3D"gmail-pe-11 gmail-pt-3"><div class=3D"gmail-rel= ative gmail-z-0 gmail-flex gmail-max-w-full"><div id=3D"gmail-code-block-vi= ewer" dir=3D"ltr" class=3D"gmail-q9tKkq_viewer gmail-cm-editor gmail-z-10 g= mail-light:cm-light gmail-dark:cm-light gmail-flex gmail-h-full gmail-w-ful= l gmail-flex-col gmail-items-stretch gmail-=CD=BCd gmail-=CD=BCr"><div clas= s=3D"gmail-cm-scroller"><pre class=3D"gmail-cm-content gmail-q9tKkq_readonl= y gmail-m-0"><p class=3D"gmail-isSelectedEnd">SpamAssassin 4.0.3 appears to= incorrectly promote a URL query parameter value into a standalone URI host= name and then performs URIDNSBL lookups against the generated domain.</p><p= class=3D"gmail-isSelectedEnd">Observed behavior:</p><p class=3D"gmail-isSe= lectedEnd">Input message contains only the following URI:</p><p class=3D"gm= ail-isSelectedEnd"><a href=3D"https://substack.com/signup?r=3Dto8ex">https:= //substack.com/signup?r=3Dto8ex</a></p><p class=3D"gmail-isSelectedEnd">Deb= ug output shows SpamAssassin correctly parsing the original URI:</p><p clas= s=3D"gmail-isSelectedEnd">Jun 20 17:04:48.788 dbg: uri: canonicalizing pars= ed uri: <a href=3D"https://substack.com/signup?r=3Dto8ex">https://substack.= com/signup?r=3Dto8ex</a><br>Jun 20 17:04:48.788 dbg: uri: cleaned uri: <a h= ref=3D"https://substack.com/signup?r=3Dto8ex">https://substack.com/signup?r= =3Dto8ex</a><br>Jun 20 17:04:48.788 dbg: uri: added host: <a href=3D"http:/= /substack.com">substack.com</a> domain: <a href=3D"http://substack.com">sub= stack.com</a></p><p class=3D"gmail-isSelectedEnd">Immediately afterward, Sp= amAssassin creates a second URI which does not exist in the message:</p><p = class=3D"gmail-isSelectedEnd">Jun 20 17:04:48.821 dbg: uri: canonicalizing = parsed uri: <a href=3D"http://to8ex">http://to8ex</a><br>Jun 20 17:04:48.82= 2 dbg: uri: cleaned uri: <a href=3D"http://to8ex">http://to8ex</a><br>Jun 2= 0 17:04:48.822 dbg: uri: cleaned uri: <a href=3D"http://www.to8ex.com/">htt= p://www.to8ex.com</a><br>Jun 20 17:04:48.822 dbg: uri: added host: <a href= =3D"http://www.to8ex.com/">www.to8ex.com</a> domain: <a href=3D"http://to8e= x.com">to8ex.com</a></p><p class=3D"gmail-isSelectedEnd">SpamAssassin then = performs URIDNSBL lookups against the generated domain:</p><p class=3D"gmai= l-isSelectedEnd">Jun 20 17:04:48.836 dbg: uridnsbl: considering host=3D<a h= ref=3D"http://www.to8ex.com/">www.to8ex.com</a>, domain=3D<a href=3D"http:/= /to8ex.com">to8ex.com</a></p><p class=3D"gmail-isSelectedEnd">Expected beha= vior:</p><p class=3D"gmail-isSelectedEnd">The query parameter value "t= o8ex" should remain data associated with the URI:</p><p class=3D"gmail= -isSelectedEnd"><a href=3D"https://substack.com/signup?r=3Dto8ex">https://s= ubstack.com/signup?r=3Dto8ex</a></p><p class=3D"gmail-isSelectedEnd">No sta= ndalone hostname or domain should be generated from the parameter value.</p= ><p></p></pre></div></div></div></div></div></div></div></div></div></div><= /div></div></div></pre></div> --00000000000033fbf50654b5d157--