Opened 62 minutes ago

Last modified 20 minutes ago

#37414 new Cleanup/optimization

Reject invalid characters in response header names and values

Reported by: Natalia Bidart Owned by:
Component: HTTP handling Version: dev
Severity: Normal Keywords: not-security
Cc: Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description

ResponseHeaders._convert_to_charset() only rejects CR and LF, so other characters that are invalid per ​RFC 9110 section 5.5 are sent as-is:

Field values containing CR, LF, or NUL characters are invalid and dangerous [...] Field values containing other CTL characters are also invalid [...]

Field names must be token characters, which Django doesn't validate at all. For example:

from django.conf import settings; settings.configure()
from django.http import HttpResponse

r = HttpResponse()
r["X-Test"] = "a\x00b"
r["X-Test\x0b"] = "1"
print(r.serialize_headers())

outputs:

b'Content-Type: text/html; charset=utf-8\r\nX-Test: a\x00b\r\nX-Test\x0b: 1'

Django could raise django.http.BadHeaderError for NUL and other C0 controls (except HTAB) and DEL in values, and for non-token characters in names, similar to what #37100 did for reason_phrase. Note that _control_chars_re can't be reused as is.

Change History (1)

comment:1 by David Smith, 20 minutes ago

Triage Stage: Unreviewed → Accepted
Note: See TracTickets for help on using tickets.
Back to Top