Aias00 opened a new issue, #6658:
URL: https://github.com/apache/shenyu/issues/6658

   - severity: High
   - files: 
`shenyu-plugin/shenyu-plugin-request/src/main/java/org/apache/shenyu/plugin/request/RequestPlugin.java:70`
   - description: The second `if` block (lines 70-73) is intended to set up 
response header dedup but its guard condition checks 
`requestHandle.getRequestHeaderUniqueStrategy()` (the *request* strategy) 
instead of `requestHandle.getRespHeaderUniqueStrategy()` (the *response* 
strategy). Copy-paste error from the block above (lines 66-69). If request 
strategy is non-null (default) but response strategy is explicitly null, 
`exchange.getAttributes().put(..., null)` on a ConcurrentHashMap-backed map 
throws NPE.
   - impact: (a) Resp dedup silently never applied when request strategy is 
null. (b) NPE when response strategy is null but request strategy is non-null.
   - suggested_fix: Change line 70 to 
`Objects.nonNull(requestHandle.getRespHeaderUniqueStrategy()) && 
StringUtils.isNotEmpty(requestHandle.getRespUniqueHeaders())`.
   - confidence: High
   - related_existing: none — #6360 is about add* overwriting; #6507 is about 
partial config. This is a distinct copy-paste bug.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to