mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-01 05:02:29 +07:00
Fix OSS-Fuzz #508087118: avoid stack overflow in str2tag
str2tag_core is recursive (one frame per character), so a long runtime input such as a fuzzer-supplied Content-Type would overflow the stack. Rewrite the runtime entry point str2tag() iteratively while keeping the recursive constexpr str2tag_core for compile-time UDL evaluation. The hash output is unchanged for all inputs.
This commit is contained in:
BIN
Binary file not shown.
@@ -767,6 +767,13 @@ TEST(ParseAcceptHeaderTest, InvalidCases) {
|
||||
EXPECT_EQ(result[0], "text/*");
|
||||
}
|
||||
|
||||
// Regression test for OSS-Fuzz #508087118: a long Content-Type ran str2tag
|
||||
// recursively (one stack frame per character) and overflowed the stack.
|
||||
TEST(Str2tagTest, LongInputDoesNotOverflowStack) {
|
||||
std::string long_content_type(60000, 'x');
|
||||
EXPECT_NO_THROW(detail::can_compress_content_type(long_content_type));
|
||||
}
|
||||
|
||||
TEST(ParseAcceptHeaderTest, ContentTypesPopulatedAndInvalidHeaderHandling) {
|
||||
Server svr;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user