Skip to content

fix(http1): reject forbidden trailer fields - #4161

Open
freedom-winds wants to merge 1 commit into
hyperium:masterfrom
freedom-winds:bugfix-001
Open

fix(http1): reject forbidden trailer fields#4161
freedom-winds wants to merge 1 commit into
hyperium:masterfrom
freedom-winds:bugfix-001

Conversation

@freedom-winds

Copy link
Copy Markdown

During a static audit of the HTTP/1 chunked-body decoding path, I found that decode_trailers() accepted every syntactically valid trailer field and inserted it directly into the trailer HeaderMap.

Specifically, a chunked request or response could include Content-Length, Transfer-Encoding, or Trailer in its trailer block. The previous implementation exposed these fields tothe application layer even though they must not be accepted as trailer fields b ecause they control or describe message framing.

The fix validates each trailer field name before inserting it into the HeaderMap. Content-Length, Transfer-Encoding, and Trailer now cause decoding to fail with io::ErrorKind::InvalidInput.

A regression test was added to verify that all three fields are rejected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant