| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This is a field that is (now) available on instances of `SimpleHTTPRequestHandler`, and which is vulnerable to a header injection attack.
There was a problem hiding this comment.
In-place mutations of the header mapping are not modeled, causing missed injection results.
Review effort: Balanced
Findings: 1
Models Python 3.15 SimpleHTTPRequestHandler.extra_response_headers as a response-header sink.
Changes:
| File | Description |
|---|---|
| Stdlib.qll | Adds header-write modeling. |
| test_extra_response_headers.py | Tests framework concepts. |
| extra_response_headers.py | Adds injection scenarios. |
| HeaderInjection.expected | Updates generated expectations. |
| 2026-09-22-python315-http-headers.md | Documents the analysis improvement. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
This is a field that is (now) available on instances of SimpleHTTPRequestHandler, and which is vulnerable to a header injection attack.