Aias00 opened a new issue, #6631:
URL: https://github.com/apache/shenyu/issues/6631
- Severity: High
- Location:
`shenyu-web/src/main/java/org/apache/shenyu/web/loader/PluginJarParser.java:60-62`
-
Description:
`pluginJar.version = properties.get("version").toString();
pluginJar.artifactId = properties.get("artifactId").toString();
pluginJar.groupId = properties.get("groupId").toString();`. `Properties.get`
returns `null` if the key is absent (hand-crafted jar, stripped
`pom.properties`, or a `pom.xml`-only jar). `.toString()` on null →
`NullPointerException`. If no `pom.properties` exists at all,
`version`/`artifactId`/`groupId` stay null and `getJarKey()` returns
`"null:null"`, colliding all such plugins into one cache slot.
-
Impact:
NPE aborts `parseJar`; in the upload path
`ShenyuLoaderService.loadExtOrUploadPlugins` catches `Exception` broadly (line
94), so the whole load cycle silently fails with only a log line. Multi-plugin
collisions on `"null:null"` corrupt the classloader cache.
-
Suggested fix:
Use `properties.getProperty(key, "")` with non-null defaults, or guard each
`get(...)` with `Objects.requireNonNull` and throw a typed `ShenyuException`
naming the jar/entry.
-
Confidence: High
- Related existing: none
---
_Identified during the 2026-08-02 deep re-scan; full list in
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]