Aias00 opened a new issue, #6719:
URL: https://github.com/apache/shenyu/issues/6719

   - Severity: Medium
   - Location:
   
`shenyu-web/src/main/java/org/apache/shenyu/web/handler/GlobalErrorHandler.java:64-66`
   - 
   Description:
   In the `ResponseStatusException` branch: `httpStatusCode = 
((ResponseStatusException) throwable).getStatusCode(); HttpStatus httpStatus = 
(HttpStatus) httpStatusCode;`. On Spring Framework 6.1, `getStatusCode()` 
returns the interface `HttpStatusCode`. `HttpStatus` is an enum implementing 
it, but `ResponseStatusException` also accepts raw `int`/`HttpStatusCode` 
codes. If any exception is created with a non-enum value (e.g. 
`HttpStatusCode.valueOf(460)`), `getStatusCode()` returns 
`DefaultHttpStatusCode` and the cast to `HttpStatus` throws 
`ClassCastException`, crashing the error handler itself and masking the 
original error with a 500 + CCE stack trace.
   - 
   Impact:
   Any plugin, third-party library, or Spring framework component that throws 
`ResponseStatusException` with a non-enum status code causes the global error 
handler to crash, replacing the real error with an unhelpful 500 + CCE.
   - 
   Suggested fix:
   Replace `(HttpStatus) httpStatusCode` with 
`HttpStatus.resolve(httpStatusCode.value())` (returns null for non-standard 
codes) and null-guard, or use `httpStatusCode.toString()`.
   - 
   Confidence: Medium — no current trigger in shenyu's own code (all use 
`HttpStatus` constants), but the cast is unconditionally unsafe for any 
third-party exception path.
   - Related existing: none
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to