llhttp icon indicating copy to clipboard operation
llhttp copied to clipboard

Does it not support whitespace before header filed name ?

Open rclijia opened this issue 1 year ago • 2 comments

The wireshark follow tcp stream :

GET /HelloWorld.html HTTP/1.1
Host:syuqqq.xudaowang.com:8021 Accept: */*
User-Agent:Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
 Connection:Keep-Alive

however, the " Connection:Keep-Alive" start with a whitespace. Does it not support whitespace before header filed name( version 9.2.1) ?

http_whitespace_before_header.zip

rclijia avatar Jun 25 '24 08:06 rclijia

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27982
Is this reason ?

rclijia avatar Jun 26 '24 01:06 rclijia

Yes, exactly. Supporting that white space would be a security problem.

ShogunPanda avatar Jun 29 '24 14:06 ShogunPanda