Skip to content

http: reject spurious CR bytes in headers#21882

Closed
bagder wants to merge 5 commits into
masterfrom
bagder/HTTP-CR-header
Closed

http: reject spurious CR bytes in headers#21882
bagder wants to merge 5 commits into
masterfrom
bagder/HTTP-CR-header

Conversation

@bagder

@bagder bagder commented Jun 6, 2026

Copy link
Copy Markdown
Member

Verified by test 2105

@bagder bagder added the HTTP label Jun 6, 2026
@github-actions github-actions Bot added the tests label Jun 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens HTTP response header parsing by rejecting embedded carriage return (CR) bytes within header lines (except for the terminal CRLF), and adds a regression test to ensure such responses fail with CURLE_WEIRD_SERVER_REPLY (8).

Changes:

  • Add an HTTP header validation step that fails the transfer if a CR byte appears within a header line (outside the final CRLF).
  • Introduce new test case test2105 covering a response header containing a spurious CR byte.
  • Register test2105 in the test data makefile so it runs in the suite.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
lib/http.c Adds detection/rejection of spurious \r bytes in received header lines.
tests/data/test2105 New regression test ensuring responses with embedded CR in headers fail with error code 8.
tests/data/Makefile.am Includes test2105 in the TESTCASES list so it is executed.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread lib/http.c
@bagder bagder marked this pull request as ready for review June 6, 2026 20:53
@bagder bagder closed this in c3c2cfb Jun 6, 2026
@bagder bagder deleted the bagder/HTTP-CR-header branch June 6, 2026 20:54
dkarpov1970 pushed a commit to dkarpov1970/curl that referenced this pull request Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants