This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch 11.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/11.0.x by this push:
     new b9e74307eb Fix potential chunked response body corruption
b9e74307eb is described below

commit b9e74307eb6e279701e312e5ce804b0f6424ea07
Author: Mark Thomas <[email protected]>
AuthorDate: Fri Oct 2 18:51:30 2026 +0100

    Fix potential chunked response body corruption
---
 .../coyote/http11/filters/ChunkedOutputFilter.java  | 21 +++++++++++++++------
 webapps/docs/changelog.xml                          |  4 ++++
 2 files changed, 19 insertions(+), 6 deletions(-)

diff --git a/java/org/apache/coyote/http11/filters/ChunkedOutputFilter.java 
b/java/org/apache/coyote/http11/filters/ChunkedOutputFilter.java
index 32f673916e..6e20ea9a6b 100644
--- a/java/org/apache/coyote/http11/filters/ChunkedOutputFilter.java
+++ b/java/org/apache/coyote/http11/filters/ChunkedOutputFilter.java
@@ -154,11 +154,17 @@ public class ChunkedOutputFilter implements OutputFilter {
 
         if (trailerFields == null) {
             // Write end chunk
-            buffer.doWrite(endChunk);
-            endChunk.position(0).limit(endChunk.capacity());
+            try {
+                buffer.doWrite(endChunk);
+            } finally {
+                endChunk.position(0).limit(endChunk.capacity());
+            }
         } else {
-            buffer.doWrite(lastChunk);
-            lastChunk.position(0).limit(lastChunk.capacity());
+            try {
+                buffer.doWrite(lastChunk);
+            } finally {
+                lastChunk.position(0).limit(lastChunk.capacity());
+            }
 
             ByteArrayOutputStream baos = new ByteArrayOutputStream(1024);
 
@@ -178,8 +184,11 @@ public class ChunkedOutputFilter implements OutputFilter {
 
             buffer.doWrite(ByteBuffer.wrap(baos.toByteArray()));
 
-            buffer.doWrite(crlfChunk);
-            crlfChunk.position(0).limit(crlfChunk.capacity());
+            try {
+                buffer.doWrite(crlfChunk);
+            } finally {
+                crlfChunk.position(0).limit(crlfChunk.capacity());
+            }
         }
         buffer.end();
     }
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index de3c973c2a..cfe8dfe129 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -194,6 +194,10 @@
         <code>CloseableURLConnection</code> unless it is certain the JAR is not
         shared. (remm)
       </fix>
+      <fix>
+        Fix possible corruption of HTTP/1.1 chunked response bodies if a
+        previous write to a chunked body fails. (markt) 
+      </fix>
     </changelog>
   </subsection>
   <subsection name="Jasper">


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to