Aias00 opened a new issue, #6616:
URL: https://github.com/apache/shenyu/issues/6616

   - severity: High
   - files: 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/model/page/PageParameter.java:59`
   - description: The `(Integer, Integer)` constructor guards `currentPage` for 
null before unboxing (line 58), but line 59 re-checks 
`Objects.isNull(currentPage)` instead of `Objects.isNull(pageSize)`: 
`this.pageSize = Objects.isNull(currentPage) || pageSize <= 0 ? 
DEFAULT_PAGE_SIZE : pageSize;`. When `currentPage` is non-null but `pageSize` 
is null, the short-circuit is false and `pageSize <= 0` unboxes a null 
`Integer`, throwing NPE.
   - impact: Any caller constructing `new PageParameter(nonNullPage, null)` 
gets NPE instead of the intended default-page-size fallback. Currently masked 
because audited controllers declare `@NotNull` on `pageSize`, but the latent 
defect remains for any new paged endpoint that omits `@NotNull`.
   - suggested_fix: Change line 59 to `Objects.isNull(pageSize) || pageSize <= 
0 ? DEFAULT_PAGE_SIZE : pageSize;`.
   - confidence: High
   - related_existing: relates to #6463 but is NOT a dup — #6463 reported "NPE 
when pageSize omitted"; this finding reports that the closed fix guards the 
wrong variable, so the NPE still occurs whenever `currentPage` is present and 
`pageSize` is null.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to