Skip to content

httpauth/digest: fix MD5 default hash handler - #1621

Merged
sreimers merged 2 commits into
mainfrom
digest_default
Sep 25, 2026
Merged

sreimers merged 2 commits into
mainfrom
digest_default

Conversation

@sreimers

@sreimers sreimers commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

rfc 7616 3.3

algorithm

  A string indicating an algorithm used to produce the digest and an
  unkeyed digest.  If this is not present, it is assumed to be
  "MD5".  If the algorithm is not understood, the challenge SHOULD
  be ignored (and a different one used, if there is more than one).

A empty algorithm could crash httpauth_digest_verify() before.

if no algorithm= parameter is provided hassh is NULL and could crash
server after digest_verify()
@sreimers
sreimers marked this pull request as ready for review September 24, 2026 19:13
@sreimers
sreimers merged commit fd6c71b into main Sep 25, 2026
39 checks passed
@sreimers
sreimers deleted the digest_default branch September 25, 2026 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant