Hello,

Currently, it is possible to have multiple lines in a HTTP headers in a cURL 
request, which then get interpreted as multiple headers:

$ch = curl_init('https://httpbin.dev/headers');
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Hello: world\r\nFoo: bar"]);
curl_exec($ch);

This sends two headers to the server (even when using HTTP/2):

{
  "headers": {
   ...
    "Foo": [
      "bar"
    ],
    "Hello": [
      "world"
    ],
  }
}

This is not supported behavior by cURL, and it is a security risk when a header 
value is under control of an attacker: they can inject arbitrary headers to the 
request.

I propose to not allow newlines in header values. Any thoughts on this? Should 
this first raise a deprecation warning before throwing a value error? I haven't 
added this to the deprecation RFC as I thought that is being finalized and made 
ready for voting soon.

Regards,

Sjoerd Langkemper

Reply via email to