python / python/cpython

http.client accepts Content-Length and chunk-size values that RFC 9112 forbids

Offen
#150,751 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

stdlib type-bug
Vorherrschende Sprache
Python
Sterne
77.2k
Forks
35.9k
PR-Merge-Kennzahlen
PR-Kennzahlen ausstehend

Beschreibung

http.client derives the response body framing from int() of the Content-Length header and the chunked chunk-size line:

  • HTTPResponse.begin: self.length = int(length)
  • HTTPResponse._read_next_chunk_size: return int(line, 16)

RFC 9112 defines Content-Length = 1*DIGIT and chunk-size = 1*HEXDIG, but int() is more permissive: it accepts a leading +/-, underscores, surrounding whitespace and, in base 16, an 0x prefix and non-ASCII digits. So values like Content-Length: +5 / 5_0 and chunk sizes -5, +5, 0x5, 1_f are accepted and used to frame the body, while an RFC-compliant front end would reject them or frame the message differently (CWE-444).

Reproducer:

import http.client, io
class S:
    def __init__(s, d): s.f = io.BytesIO(d)
    def makefile(s, *a, **k): return s.f
def parse(raw):
    r = http.client.HTTPResponse(S(raw)); r.begin(); return r
raw = b'HTTP/1.1 200 OK\r\nTransfer-Encoding: chunked\r\n\r\n+5\r\nHELLO\r\n0\r\n\r\n'
print(parse(raw).read())            # b'HELLO' -- '+5' is not a HEXDIG
raw = b'HTTP/1.1 200 OK\r\nContent-Length: 5_0\r\n\r\n' + b'A'*50
print(parse(raw).length)            # 50 -- '5_0' is not 1*DIGIT

The body-framing tokens should be validated against the grammar before being passed to int().

Linked PRs
  • gh-150752

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne bei HTTPResponse.begin und HTTPResponse._read_next_chunk_size, wo Content-Length- und chunk-size-Werte mit int() konvertiert werden. Validiere jedes Body-Framing-Token vor der Konvertierung anhand seiner Grammatik gemäß RFC 9112 und bestätige, dass die nicht konformen Werte des Reproducers abgelehnt oder nicht mehr für das Framing verwendet werden.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
networking, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.