Aias00 opened a new issue, #6719: URL: https://github.com/apache/shenyu/issues/6719
- Severity: Medium - Location: `shenyu-web/src/main/java/org/apache/shenyu/web/handler/GlobalErrorHandler.java:64-66` - Description: In the `ResponseStatusException` branch: `httpStatusCode = ((ResponseStatusException) throwable).getStatusCode(); HttpStatus httpStatus = (HttpStatus) httpStatusCode;`. On Spring Framework 6.1, `getStatusCode()` returns the interface `HttpStatusCode`. `HttpStatus` is an enum implementing it, but `ResponseStatusException` also accepts raw `int`/`HttpStatusCode` codes. If any exception is created with a non-enum value (e.g. `HttpStatusCode.valueOf(460)`), `getStatusCode()` returns `DefaultHttpStatusCode` and the cast to `HttpStatus` throws `ClassCastException`, crashing the error handler itself and masking the original error with a 500 + CCE stack trace. - Impact: Any plugin, third-party library, or Spring framework component that throws `ResponseStatusException` with a non-enum status code causes the global error handler to crash, replacing the real error with an unhelpful 500 + CCE. - Suggested fix: Replace `(HttpStatus) httpStatusCode` with `HttpStatus.resolve(httpStatusCode.value())` (returns null for non-standard codes) and null-guard, or use `httpStatusCode.toString()`. - Confidence: Medium — no current trigger in shenyu's own code (all use `HttpStatus` constants), but the cast is unconditionally unsafe for any third-party exception path. - Related existing: none --- _Identified during the 2026-08-02 deep re-scan; full list in [`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
