Skip to content

Commit 6b837d4

Browse files
authored
Bound header field name size before validating (#296)
1 parent e0c4f9d commit 6b837d4

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

‎python_multipart/multipart.py‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1249,6 +1249,11 @@ def data_callback(name: CallbackName, end_i: int, remaining: bool = False) -> No
12491249
# validate the whole span at once instead of byte by byte.
12501250
colon = data.find(b":", i, length)
12511251
end = colon if colon != -1 else length
1252+
1253+
# Enforce the size limit before slicing and validating, so an oversized header
1254+
# name fails fast instead of copying and scanning a potentially huge span.
1255+
advance_header_size(end - i if colon == -1 else end - i + 1)
1256+
12521257
field = data[i:end]
12531258
if field.translate(None, TOKEN_CHARS):
12541259
bad = next(b for b in field if b not in TOKEN_CHARS_SET)
@@ -1260,10 +1265,8 @@ def data_callback(name: CallbackName, end_i: int, remaining: bool = False) -> No
12601265
index += end - i
12611266
if colon == -1:
12621267
# Field name continues into the next chunk.
1263-
advance_header_size(end - i)
12641268
i = length
12651269
else:
1266-
advance_header_size(end - i + 1)
12671270
# A 0-length header is an error.
12681271
if index == 0:
12691272
msg = "Found 0-length header at %d" % (i,)

0 commit comments

Comments
 (0)