bughelp wanted
倉庫指標
- 星標
- (2,929 顆星)
- PR 合併指標
- (PR 指標待抓取)
描述
URL parameters which contain a space in the value do not get the usual URL encoding (ex. " " becomes "+" or "%20"). This results in malformed HTTP/1.1 requests. For example, if my yaml specification has a type like:
network:
name: network
in: query
required: true
schema:
type: string
enum:
- "Internal"
- "External Users"
- "External Networks"
then the following GET requests will be created:
GET /config?network=Internal HTTP/1.1
GET /config?network=External Users HTTP/1.1
GET /config?network=External Networks HTTP/1.1
This doesn't get recognized properly and leads to erroneous fuzzing cases for parameters which are supposed to contain a space in them.