libmicrohttpd

HTTP/1.x server C library (MHD 1.x, stable)
Log | Files | Refs | Submodules | README | LICENSE

commit 75549625f0ba6aa56ffa4e84eedb53b5320f449f
parent 95e54a45102eccb9a9ae2d86818fa95c3cea4332
Author: Christian Grothoff <christian@grothoff.org>
Date:   Wed, 29 Jul 2026 13:17:30 +0200

fix over-writing of version string with network data read after parsing header

Diffstat:
Msrc/microhttpd/connection.c | 10++++++++++
1 file changed, 10 insertions(+), 0 deletions(-)

diff --git a/src/microhttpd/connection.c b/src/microhttpd/connection.c @@ -6723,6 +6723,16 @@ get_req_headers (struct MHD_Connection *c, bool process_footers) { last_elmnt_end = c->rq.version + HTTP_VER_LEN; } + /* The request line strings (method, url, version) remain visible to + the application for the whole request, and the last received header + is not necessarily above them: when it is not, reclaiming down to + the header end puts the read buffer on top of the version string, + and the next recv() overwrites the terminator the application is + about to read through. Never reclaim below the end of the request + line. */ + if ((NULL != c->rq.version) && + (last_elmnt_end < c->rq.version + HTTP_VER_LEN)) + last_elmnt_end = c->rq.version + HTTP_VER_LEN; /* Check that @a last_elmnt_end points into the request that has just been parsed, which lives entirely between the start of the request line and the current read buffer