Skip to content

Reject malformed HTTP/2 response headers - #712

Open
arturobernalg wants to merge 1 commit into
apache:masterfrom
arturobernalg:h2-reject-malformed-response-headers
Open

arturobernalg wants to merge 1 commit into
apache:masterfrom
arturobernalg:h2-reject-malformed-response-headers

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

HTTP/2 response framing requires informational responses not to terminate the stream and trailer field sections to carry END_STREAM.

Reject:

  • informational (1xx) response headers carrying END_STREAM
  • response trailer headers without END_STREAM

This aligns the client-side response handling with RFC 9113 section 8.1:

https://www.rfc-editor.org/rfc/rfc9113.html#section-8.1

RFC 9113 states that a HEADERS frame carrying an informational status code together with END_STREAM is malformed, and that trailer fields are carried in a field block that terminates the stream.

Reject informational responses carrying END_STREAM and response
trailers without END_STREAM as required by RFC 9113 section 8.1.
@arturobernalg
arturobernalg requested a review from ok2c September 30, 2026 10:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants