Skip to content

fix: guard invalid response headers and trailers - #7034

Open
mcollina wants to merge 1 commit into
fastify:mainfrom
mcollina:fix/http2-invalid-response-headers
Open

mcollina wants to merge 1 commit into
fastify:mainfrom
mcollina:fix/http2-invalid-response-headers

Conversation

@mcollina

Copy link
Copy Markdown
Member

Remove connection-specific headers forbidden by HTTP/2 before Fastify writes managed responses, including Web Response and stream paths. Also validate trailer metadata and contain deferred trailer errors so invalid application-supplied values cannot escape as uncaught exceptions.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 17, 2026
Comment thread lib/reply.js
}

const te = reply.getHeader('te')
if (te !== undefined && !isValidHttp2Te(te)) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why TE is not removed from HTTP/2 responses as well?

@gurgunday

Copy link
Copy Markdown
Member

Isn't this a breaking change?

@jean-michelet

Copy link
Copy Markdown
Member

I would consider this a bug fix rather than a breaking change. HTTP/2-invalid headers are removed, and users relying on invalid trailers should fix their code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants