RFC 7540#8.1.2.1 mandates that pseudo-headers defined for requests must not appear in responses. When converting an HTTP/2 response to HTX, h2.c already rejects a response carrying :authority, :method, :path or :scheme, but the mask used for that check omits H2_PHDR_FND_PROT. As a result a backend HTTP/2 response that contains the request-only ":protocol" pseudo-header (defined by RFC 8441 for Extended CONNECT) is accepted and forwarded to the client instead of being rejected.
Add H2_PHDR_FND_PROT to the response-side rejection mask so that ":protocol" is handled like the other request pseudo-headers and such a response yields a 502 instead of being forwarded. There is no known security impact: the offending pseudo-header does not appear in the emitted HTTP/1 response (which is byte-identical to that of a valid one); the only effect is that a malformed response is tolerated instead of being rejected. This should be backported as far back as 2.4, where the ":protocol" pseudo-header (H2_PHDR_FND_PROT) was introduced; the maintainer may narrow the range to the currently maintained branches. Signed-off-by: Turhan ACAR <[email protected]> --- src/h2.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/h2.c b/src/h2.c index c66f79d..4821feb 100644 --- a/src/h2.c +++ b/src/h2.c @@ -751,8 +751,8 @@ int h2_make_htx_response(struct http_hdr *list, struct htx *htx, unsigned int *m goto fail; } - /* RFC7540#8.1.2.1 mandates to reject request pseudo-headers */ - if (fields & (H2_PHDR_FND_AUTH|H2_PHDR_FND_METH|H2_PHDR_FND_PATH|H2_PHDR_FND_SCHM)) + /* Reject request pseudo-headers, including RFC8441's :protocol. */ + if (fields & (H2_PHDR_FND_AUTH|H2_PHDR_FND_METH|H2_PHDR_FND_PATH|H2_PHDR_FND_SCHM|H2_PHDR_FND_PROT)) goto fail; /* Let's dump the response now if not yet emitted. */ -- 2.50.1 (Apple Git-155)

