|
86 | 86 | "description": "netmask is not a part of ipv4 address", |
87 | 87 | "data": "192.168.1.0/24", |
88 | 88 | "valid": false |
| 89 | + }, |
| 90 | + { |
| 91 | + "description": "leading zero in last octet is invalid in v1 (anti-octal)", |
| 92 | + "comment": "JSON Schema v1 moves to strict anti-octal rules (like RFC 3986 dec-octet) to prevent vulnerabilities like CVE-2021-28918.", |
| 93 | + "data": "192.168.0.01", |
| 94 | + "valid": false |
| 95 | + }, |
| 96 | + { |
| 97 | + "description": "leading whitespace is invalid", |
| 98 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 99 | + "data": " 192.168.0.1", |
| 100 | + "valid": false |
| 101 | + }, |
| 102 | + { |
| 103 | + "description": "trailing whitespace is invalid", |
| 104 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 105 | + "data": "192.168.0.1 ", |
| 106 | + "valid": false |
| 107 | + }, |
| 108 | + { |
| 109 | + "description": "trailing newline is invalid", |
| 110 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 111 | + "data": "192.168.0.1\n", |
| 112 | + "valid": false |
| 113 | + }, |
| 114 | + { |
| 115 | + "description": "hexadecimal notation is invalid", |
| 116 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT (requires DIGIT, forbids alpha/hex)", |
| 117 | + "data": "0x7f.0.0.1", |
| 118 | + "valid": false |
| 119 | + }, |
| 120 | + { |
| 121 | + "description": "octal notation explicit is invalid", |
| 122 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT (requires DIGIT, forbids alpha)", |
| 123 | + "data": "0o10.0.0.1", |
| 124 | + "valid": false |
| 125 | + }, |
| 126 | + { |
| 127 | + "description": "empty part (double dot) is invalid", |
| 128 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 129 | + "data": "192.168..1", |
| 130 | + "valid": false |
| 131 | + }, |
| 132 | + { |
| 133 | + "description": "leading dot is invalid", |
| 134 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 135 | + "data": ".192.168.0.1", |
| 136 | + "valid": false |
| 137 | + }, |
| 138 | + { |
| 139 | + "description": "trailing dot is invalid", |
| 140 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 141 | + "data": "192.168.0.1.", |
| 142 | + "valid": false |
| 143 | + }, |
| 144 | + { |
| 145 | + "description": "minimum valid IPv4 address", |
| 146 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT", |
| 147 | + "data": "0.0.0.0", |
| 148 | + "valid": true |
| 149 | + }, |
| 150 | + { |
| 151 | + "description": "maximum valid IPv4 address", |
| 152 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT", |
| 153 | + "data": "255.255.255.255", |
| 154 | + "valid": true |
| 155 | + }, |
| 156 | + { |
| 157 | + "description": "empty string is invalid", |
| 158 | + "comment": "RFC 2673, Section 3.2: dotted-quad requires 4 decbytes", |
| 159 | + "data": "", |
| 160 | + "valid": false |
| 161 | + }, |
| 162 | + { |
| 163 | + "description": "plus sign is invalid", |
| 164 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT (forbids symbols)", |
| 165 | + "data": "+1.2.3.4", |
| 166 | + "valid": false |
| 167 | + }, |
| 168 | + { |
| 169 | + "description": "negative sign is invalid", |
| 170 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT (forbids symbols)", |
| 171 | + "data": "-1.2.3.4", |
| 172 | + "valid": false |
| 173 | + }, |
| 174 | + { |
| 175 | + "description": "exponential notation is invalid", |
| 176 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT (forbids alpha)", |
| 177 | + "data": "1e2.0.0.1", |
| 178 | + "valid": false |
| 179 | + }, |
| 180 | + { |
| 181 | + "description": "alpha characters are invalid", |
| 182 | + "comment": "RFC 2673, Section 3.2: decbyte = 1*3DIGIT (forbids alpha)", |
| 183 | + "data": "192.168.a.1", |
| 184 | + "valid": false |
| 185 | + }, |
| 186 | + { |
| 187 | + "description": "internal whitespace is invalid", |
| 188 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 189 | + "data": "192. 168.0.1", |
| 190 | + "valid": false |
| 191 | + }, |
| 192 | + { |
| 193 | + "description": "tab character is invalid", |
| 194 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 195 | + "data": "192.168.0.1\t", |
| 196 | + "valid": false |
| 197 | + }, |
| 198 | + { |
| 199 | + "description": "with port number is invalid", |
| 200 | + "comment": "RFC 2673, Section 3.2: dotted-quad = decbyte \".\" decbyte \".\" decbyte \".\" decbyte", |
| 201 | + "data": "192.168.0.1:80", |
| 202 | + "valid": false |
| 203 | + }, |
| 204 | + { |
| 205 | + "description": "single octet out of range in last position", |
| 206 | + "comment": "RFC 2673 limits the semantic value of decbyte to 255.", |
| 207 | + "data": "192.168.0.256", |
| 208 | + "valid": false |
89 | 209 | } |
90 | 210 | ] |
91 | 211 | } |
|
0 commit comments