Aias00 opened a new issue, #6802: URL: https://github.com/apache/shenyu/issues/6802
- severity: Medium-High - files: `shenyu-plugin-logging-console/.../LoggingConsolePlugin.java:80` (`private static String dataDesensitizeAlg = ...`), `:88` (`new KeyWordMatch(Collections.emptySet())` always), `:95` (`new KeyWordMatch(keywordSets)` + `dataDesensitizeAlg = ...` when desensitization on), `:132,:140` (use). `KeyWordMatch.java:46` (`Pattern.compile(sb.toString())` in constructor) - description: (a) `doExecute` constructs a fresh `KeyWordMatch` on every request → `Pattern.compile` per request whenever logging-console is enabled. (b) `dataDesensitizeAlg` is a `static` field reassigned per request → concurrent requests overwrite each other's algorithm choice and pass the wrong alg to `DataDesensitizeUtils` for a different request's body (data race / cross-request desensitization leak — also a correctness defect). - impact: Per-request regex compile; cross-request algorithm leakage. - suggested_fix: Cache `KeyWordMatch` per rule-handle (rule-keyed like `CACHED_HANDLE`); make `dataDesensitizeAlg` an instance field or pass it through the decorator chain. - confidence: High - related_existing: PERF-26 covers `AbstractLoggingPlugin` allocation; this is the separate `LoggingConsolePlugin` class with its own per-request `KeyWordMatch` + the static-field race. #6511 (logging desensitization leak across concurrent requests) is the AbstractLoggingPlugin path — different class. --- _Identified during the 2026-08-02 deep re-scan; full list in [`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
