Aias00 opened a new issue, #6629:
URL: https://github.com/apache/shenyu/issues/6629

   - Severity: High
   - Location:
   
`shenyu-plugin/shenyu-plugin-global/src/main/java/org/apache/shenyu/plugin/global/DefaultShenyuContextBuilder.java:62`
 (`decoratorMap.get(buildData.getLeft()).decorator(...)`); trigger at `:68` 
(`rpc_type` request header)
   - 
   Description:
   `build()` does `decoratorMap.get(buildData.getLeft()).decorator(...)` with 
no null guard. `buildData.getLeft()` is the rpc type string. `buildData` line 
68 reads `headers.getFirst("rpc_type")` directly from the incoming HTTP 
request. A client sending `rpc_type: bogus` makes `buildData` return 
`Pair.of("bogus", new MetaData())`. `"bogus"` is not a key in `decoratorMap` → 
`get` returns null → `.decorator(...)` NPEs inside `GlobalPlugin.execute` → 500 
on the request thread. Also fires if a registered `MetaData.rpcType` has no 
matching decorator bean (plugin module absent).
   - 
   Impact:
   Single unauthenticated request with a bogus `rpc_type` header crashes 
`GlobalPlugin` with NPE (trivial DoS); misconfigured metadata crashes all 
requests of that rpc type.
   - 
   Suggested fix:
   Validate `rpcType` against `decoratorMap.containsKey(...)`; fall back to 
HTTP decorator or reject with 400. Treat the client `rpc_type` header as 
untrusted.
   - 
   Confidence: High
   - Related existing: FUNC-C4 (#6556) is websocket `Upgrade` case-sensitivity 
in the same method but a different branch; this is the missing null-guard on 
the decorator-map lookup.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to