Duplicate Content-Type Header Parsing Issue #2600
Unanswered
TUO-Wu
asked this question in
Potential Issue
Replies: 1 comment 2 replies
-
Just like HTTP methods, I think there are more important issues than the one you raised, for example, whether or not to allow leading zeros in Because Uvicorn seems to allow this in the
|
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Version
bfa754e
Platform
Ubuntu 11.4.0-1ubuntu1~22.04
Description
Hello, I may have found a bug in uvicorn's parsing of HTTP requests with duplicate
Content-Type
header.RFC 9110 says this:
Uvicorn does not reject such requests. For example:
If different implementations have different error handling behaviors, there may be potential interoperability and security issues. So I might suggest rejecting such requests.
Beta Was this translation helpful? Give feedback.
All reactions