Opened 62 minutes ago
Last modified 20 minutes ago
#37414 new Cleanup/optimization
Reject invalid characters in response header names and values
| Reported by: | Natalia Bidart | Owned by: | |
|---|---|---|---|
| Component: | HTTP handling | Version: | dev |
| Severity: | Normal | Keywords: | not-security |
| Cc: | Triage Stage: | Accepted | |
| Has patch: | no | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
ResponseHeaders._convert_to_charset() only rejects CR and LF, so other characters that are invalid per RFC 9110 section 5.5 are sent as-is:
Field values containing CR, LF, or NUL characters are invalid and dangerous [...] Field values containing other CTL characters are also invalid [...]
Field names must be token characters, which Django doesn't validate at all. For example:
from django.conf import settings; settings.configure() from django.http import HttpResponse r = HttpResponse() r["X-Test"] = "a\x00b" r["X-Test\x0b"] = "1" print(r.serialize_headers())
outputs:
b'Content-Type: text/html; charset=utf-8\r\nX-Test: a\x00b\r\nX-Test\x0b: 1'
Django could raise django.http.BadHeaderError for NUL and other C0 controls (except HTAB) and DEL in values, and for non-token characters in names, similar to what #37100 did for reason_phrase. Note that _control_chars_re can't be reused as is.