PAC-X012 · shexpmatch-middle-asterisk

Wildcard inside a domain label

medium · Security and fail-safety

shExpMatch(host, "corp*.example") matches corp.example and corp-cdn.example but also corpevil.example. A wildcard inside a label spans arbitrary registrable names.

Why it matters

* in shExpMatch matches any run of characters, including dots. corp*.example is true for corp.example, corp1.example and corpevil.example, and for corp.evil.example-style names because the wildcard also absorbs dots. The owner’s lab confirmed the same with example*.com (2026-05-20). The pattern is almost always an attempt to cover a few related domains; list them explicitly instead.

How to fix

Enumerate the intended domains (host == "corp.example" || host == "corp-cdn.example") or use "*.corp.example" for subdomains.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "corp*.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "corp.example" || host == "corp-cdn.example" || shExpMatch(host, "*.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
pacparserA pattern of the form "name*.tld" matches look-alike names with extra characters before the TLD.lab, verified 2026-05-20

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References