Uh oh!
There was an error while loading. Please reload this page.
Reject CR/LF in raw multipart part-header fields - #2244
Merged
Conversation
MultipartPart wrote dispositionType, contentType, contentTransferEncoding, contentId, and custom part-header names and values straight into the header without validation, while name and filename were already escaped. A CR or LF in any of these injects extra part headers or splits the body. Reject CR/LF in these raw fields and fail closed; a legitimate value never contains them.
Uh oh!
There was an error while loading. Please reload this page.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
MultipartPartwrites several part-header fields (dispositionType,contentType,contentTransferEncoding,contentId, and custom header names/values) directly into the multipart header without validating CR/LF characters. This allows header injection or multipart body splitting. Whilenameandfilenamewere hardened in #2203, these fields remained unprotected.Modification
Add
asciiHeaderBytes(String)to reject CR/LF characters before encoding to US-ASCII, and use it for all raw part-header fields.nameandfilenamecontinue using their existing quoted-string escaping.Result
Raw part-header fields now fail fast on CR/LF input, preventing header injection while leaving valid values unaffected.