Binary HTTP field-section length includes its own prefix
Fixed in: main fix commit; v2026.09.21.00 still contains the old parser
details
- Finding IDs
- F-PROXYGEN-BINARYHTTP-001
- Status
- fixed on main (release not confirmed)
- Fixed in
- main fix commit; v2026.09.21.00 still contains the old parser
- Note
- A crafted Binary HTTP message can exercise the known-length header parser, where the bytes used to encode the section length were included in the section byte count. The 21 September 2026 change starts a separate fieldSectionParsed counter at zero, bounds the field-section cursor and rejects excess consumption. This closes the recorded framing error in HTTPBinaryCodec. The inspected v2026.09.21.00 release was produced before that change and retains the old implementation. The public evidence supports a parser-boundary fix on main, not confirmed request smuggling through a particular deployed proxy chain or a fixed stable release. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-PROXYGEN-BINARYHTTP-001: Input / state handling. Incorrect length accounting shifts the boundary between a Binary HTTP header section and the following data. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-PROXYGEN-BINARYHTTP-001
Security area (1seal assessment): Integrity. Incorrect length accounting shifts the boundary between a Binary HTTP header section and the following data. Reviewed 26 Sep 2026.