diff --git a/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql b/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql index a9109e6a5ca..8aa7dae4c27 100644 --- a/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql +++ b/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql @@ -20,8 +20,9 @@ import DataFlow::PathGraph */ bindingset[pattern] predicate isIncompleteHostNameRegexpPattern(string pattern, string hostPart) { - hostPart = pattern - .regexpCapture("(?i).*" + + hostPart = + pattern + .regexpCapture("(?i).*?" + // an unescaped single `.` "(?