Skip to content

🛡️ Sentinel: [HIGH] Fix HTTP Response Splitting via environment variables in headers - #11

Open
tejjasdev wants to merge 1 commit into
mainfrom
sentinel/fix-crlf-injection-5345215275529288283
Open

tejjasdev wants to merge 1 commit into
mainfrom
sentinel/fix-crlf-injection-5345215275529288283

Conversation

@tejjasdev

Copy link
Copy Markdown
Owner

🚨 Severity: HIGH
💡 Vulnerability: HTTP Response Splitting (CRLF injection) via environment variable expansion in headers.
🎯 Impact: An environment variable containing \r\n could be expanded into a header value, splitting the HTTP response and allowing injection of malicious headers or body content.
🔧 Fix: Sanitized expanded header values by replacing control characters (like \r\n) with spaces before rendering the HTTP response.
✅ Verification: Added a test case TestResponderRenderSanitizesHeaders to verify CRLF injection is prevented. run make check.


PR created automatically by Jules for task 5345215275529288283 started by @tejjasdev

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant