python / python/cpython

http.client accepts Content-Length and chunk-size values that RFC 9112 forbids

Aperta
#150,751 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

stdlib type-bug
Lingua principale
Python
Stelle
77.2k
Fork
35.9k
Metriche di merge delle PR
Metriche PR in attesa

Descrizione

http.client derives the response body framing from int() of the Content-Length header and the chunked chunk-size line:

  • HTTPResponse.begin: self.length = int(length)
  • HTTPResponse._read_next_chunk_size: return int(line, 16)

RFC 9112 defines Content-Length = 1*DIGIT and chunk-size = 1*HEXDIG, but int() is more permissive: it accepts a leading +/-, underscores, surrounding whitespace and, in base 16, an 0x prefix and non-ASCII digits. So values like Content-Length: +5 / 5_0 and chunk sizes -5, +5, 0x5, 1_f are accepted and used to frame the body, while an RFC-compliant front end would reject them or frame the message differently (CWE-444).

Reproducer:

import http.client, io
class S:
    def __init__(s, d): s.f = io.BytesIO(d)
    def makefile(s, *a, **k): return s.f
def parse(raw):
    r = http.client.HTTPResponse(S(raw)); r.begin(); return r
raw = b'HTTP/1.1 200 OK\r\nTransfer-Encoding: chunked\r\n\r\n+5\r\nHELLO\r\n0\r\n\r\n'
print(parse(raw).read())            # b'HELLO' -- '+5' is not a HEXDIG
raw = b'HTTP/1.1 200 OK\r\nContent-Length: 5_0\r\n\r\n' + b'A'*50
print(parse(raw).length)            # 50 -- '5_0' is not 1*DIGIT

The body-framing tokens should be validated against the grammar before being passed to int().

Linked PRs
  • gh-150752

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia da HTTPResponse.begin e HTTPResponse._read_next_chunk_size, dove i valori di Content-Length e chunk-size vengono convertiti con int(). Valida ogni token di body framing in base alla relativa grammatica di RFC 9112 prima della conversione e verifica che i valori non conformi del reproducer vengano rifiutati o non vengano più utilizzati per il framing.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
python
Ambito
networking, security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Ferma
Chiarezza
Specificata chiaramente
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.