Skip to content

HPACK: reject integer decoding overflow#627

Merged
arturobernalg merged 1 commit intoapache:masterfrom
arturobernalg:overflow
Feb 19, 2026
Merged

HPACK: reject integer decoding overflow#627
arturobernalg merged 1 commit intoapache:masterfrom
arturobernalg:overflow

Conversation

@arturobernalg
Copy link
Member

This change hardens HPACK integer decoding against signed int overflow.

When decoding continuation bytes, the accumulated value can exceed Integer.MAX_VALUE and wrap negative,
which may surface later as unchecked exceptions (e.g. invalid index / length) instead of a clean HPackException.

@arturobernalg arturobernalg requested a review from ok2c February 19, 2026 06:10
Guard HPACK integer decoding against signed overflow and throw HPackException instead.
Adds a regression test for crafted values exceeding Integer.MAX_VALUE.
@arturobernalg arturobernalg merged commit b4c8268 into apache:master Feb 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments