This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat-connectors.git


The following commit(s) were added to refs/heads/main by this push:
     new 4be549347 Add a lower bounds check for encoded response headers
4be549347 is described below

commit 4be549347e136a14d325ebbcfde8c9d0f74dd4b6
Author: Mark Thomas <[email protected]>
AuthorDate: Mon Sep 28 14:44:02 2026 +0100

    Add a lower bounds check for encoded response headers
    
    Should never happen but harden against a potential origin server bug
---
 native/common/jk_ajp_common.c     | 2 +-
 xdocs/miscellaneous/changelog.xml | 3 +++
 2 files changed, 4 insertions(+), 1 deletion(-)

diff --git a/native/common/jk_ajp_common.c b/native/common/jk_ajp_common.c
index 9c940541b..0945b2bba 100644
--- a/native/common/jk_ajp_common.c
+++ b/native/common/jk_ajp_common.c
@@ -780,7 +780,7 @@ static int ajp_unmarshal_response(jk_msg_buf_t *msg,
                     /* Consume bytes just peeked with jk_b_pget_int */
                     jk_b_get_int(msg);
                     name = name & 0X00FF;
-                    if (name <= SC_RES_HEADERS_NUM) {
+                    if (name > 0 && name <= SC_RES_HEADERS_NUM) {
                         d->header_names[i] =
                             (char *)long_res_header_for_sc(name);
                     }
diff --git a/xdocs/miscellaneous/changelog.xml 
b/xdocs/miscellaneous/changelog.xml
index 5ca916843..4253b3b13 100644
--- a/xdocs/miscellaneous/changelog.xml
+++ b/xdocs/miscellaneous/changelog.xml
@@ -116,6 +116,9 @@
       <update>
         Constify static arrays of string constants. (rjung)
       </update>
+      <add>
+        A a lower bounds check for common response header codes. (markt)
+      </add>
     </changelog>
   </subsection>
   <subsection name="Docs">


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to