Skip to content

Reject non-SP whitespace in proxy CONNECT status lines - #1320

Closed
fewensa wants to merge 1 commit into
mainfrom
codeon/fewensa/FWN-4/a1-aee2c17179614378bbda81d9e7a7077a
Closed

fewensa wants to merge 1 commit into
mainfrom
codeon/fewensa/FWN-4/a1-aee2c17179614378bbda81d9e7a7077a

Conversation

@fewensa

@fewensa fewensa commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Proxy CONNECT status-line parsing now rejects every whitespace character except literal ASCII space, while preserving the shared generic HTTP parser behavior.

Synchronous and asynchronous regression coverage covers non-SP separators, reason-phrase whitespace, and missing separators; existing 200, informational, size, and non-200 handling remains unchanged.

Closes #1164

codeon:
  version: 1
  authority: FWN-4
  description: |-
    Guard proxy CONNECT status-line parsing against every whitespace character except ASCII space while preserving shared HTTP parsing. Extend synchronous and asynchronous proxy regression coverage for reason-phrase whitespace.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@fewensa fewensa closed this Oct 1, 2026
@fewensa
fewensa deleted the codeon/fewensa/FWN-4/a1-aee2c17179614378bbda81d9e7a7077a branch October 1, 2026 00:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reject non-SP whitespace in proxy CONNECT response status lines

1 participant