Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

header_rewrite: Parser::preprocess() indexes tokens[0] after pop_back() can empty the vector

Chiusa
#13,639 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

@bneradt ci sta già lavorando.

Dal 8/9/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

Summary

Parser::preprocess() in header_rewrite can pop the only token off the vector and then index tokens[0] without checking whether anything is left.

Detail

plugins/header_rewrite/parser.cc:194 consumes a trailing flags section:

if (tokens.size() > 0) {
  std::string m = tokens[tokens.size() - 1];

  if (!m.empty() && (m[0] == '[')) {
    if (m[m.size() - 1] == ']') {
      ...
      tokens.pop_back(); // consume it, so we don't concatenate it into the value
    } else {
      ...
    }
  }
}

// Special case for "conditional" values
if (tokens[0].substr(0, 2) == "%{") {

A configuration line whose only token is a flags section, [L] on a line by itself for instance, gives tokens.size() == 1. The pop_back() empties the vector, and the very next statement indexes tokens[0].

std::vector::operator[] does no bounds checking, so this is an out-of-bounds read on a configuration file that a user can write.

Proposed fix

An if (tokens.empty()) guard after the pop_back(), returning false with a TSError describing the offending line. A flags-only line is not a valid rule, so rejecting it with a message beats reading past the end of the vector.

Context

Pre-existing, and adjacent to a hunk in PR #13591. Filing it separately to keep that PR purely mechanical.

Lingua principale
C++
Stelle
2k
Fork
878
Merge medio
3g 16h
PR unite (30g)
91

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di apache/trafficserver

Tutte le issue di apache/trafficserver

Issue simili

Altre issue su C++

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.