From b8b01027603ae53fdebc7c63c4dacf0908eaef82 Mon Sep 17 00:00:00 2001 From: Christopher Faulet Date: Tue, 9 Jul 2024 08:15:14 +0200 Subject: [PATCH] BUG/MINOR: h1: Fail to parse empty transfer coding names Empty transfer coding names, inside a comma-separated list, are already rejected. But it is only by chance. Today, it is detected as an unknown coding names (not "chunked" concretly). Then, it is handled by the H1 multiplexer as an error and a 422-Unprocessable-Content response is returned. So, the error is properly detected in this case, but it is not accurate. A 400-bad-request response must be returned instead. Then, it is better to catch the error during the header parsing. It is the purpose of this patch. This patch should be backported as far as 2.6. --- src/h1.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/src/h1.c b/src/h1.c index bbaa2f67c..ff3f5ae9a 100644 --- a/src/h1.c +++ b/src/h1.c @@ -147,7 +147,12 @@ int h1_parse_xfer_enc_header(struct h1m *h1m, struct ist value) word.len--; h1m->flags &= ~H1_MF_CHNK; - if (isteqi(word, ist("chunked"))) { + + /* empty values are forbidden */ + if (!word.len) + goto fail; + + else if (isteqi(word, ist("chunked"))) { if (h1m->flags & H1_MF_TE_CHUNKED) { /* cf RFC7230#3.3.1 : A sender MUST NOT apply * chunked more than once to a message body