Aias00 opened a new issue, #6628:
URL: https://github.com/apache/shenyu/issues/6628

   - Severity: High
   - Location:
   
`shenyu-web/src/main/java/org/apache/shenyu/web/filter/CollapseSlashesFilter.java:36-38`
   - 
   Description:
   The filter computes `newPath = 
request.getURI().getRawPath().replaceAll("/{2,}", "/")` (path-only string, no 
query/fragment), then calls `request.getURI().resolve(newPath)`. Per 
`java.net.URI` resolution semantics, resolving a relative reference with only a 
path component **replaces** the query and fragment of the base URI with null. 
E.g. `URI.create("http://h/a//b?q=1#f";).resolve("/a/b")` produces 
`http://h/a/b` — query and fragment silently lost.
   - 
   Impact:
   When `collapseSlashes=true`, any request with double-slashes in the path AND 
a query string loses all query parameters. Breaks pagination, search, API key 
passing, query-param-dependent routing.
   - 
   Suggested fix:
   Reconstruct the URI preserving query/fragment: 
`UriComponentsBuilder.fromUri(request.getURI()).replacePath(newPath).build().toUri()`.
   - 
   Confidence: High
   - Related existing: PERF-03 covers regex recompilation perf in the same 
filter, not the query-loss functional bug.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to