-
Notifications
You must be signed in to change notification settings - Fork 111
Comparing changes
Open a pull request
base repository: ESP32Async/ESPAsyncWebServer
base: v3.11.1
head repository: ESP32Async/ESPAsyncWebServer
compare: v3.11.2
- 15 commits
- 24 files changed
- 6 contributors
Commits on Jun 8, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 88d5412 - Browse repository at this point
Copy the full SHA 88d5412View commit details -
Configuration menu - View commit details
-
Copy full SHA for dd2e9a6 - Browse repository at this point
Copy the full SHA dd2e9a6View commit details
Commits on Jun 9, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 6c42da6 - Browse repository at this point
Copy the full SHA 6c42da6View commit details -
Merge pull request #446 from MitchBradley/FixFS
For examples/arduino_emulator, removed dependency on arduino-esp32
Configuration menu - View commit details
-
Copy full SHA for 3469e82 - Browse repository at this point
Copy the full SHA 3469e82View commit details
Commits on Jun 19, 2026
-
Bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Configuration menu - View commit details
-
Copy full SHA for b61a94e - Browse repository at this point
Copy the full SHA b61a94eView commit details -
Merge pull request #448 from ESP32Async/dependabot/github_actions/act…
…ions/checkout-7 Bump actions/checkout from 6 to 7
Configuration menu - View commit details
-
Copy full SHA for e345b1e - Browse repository at this point
Copy the full SHA e345b1eView commit details
Commits on Jun 24, 2026
-
Bump actions/cache from 5 to 6
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v5...v6) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Configuration menu - View commit details
-
Copy full SHA for db8e7b4 - Browse repository at this point
Copy the full SHA db8e7b4View commit details -
Merge pull request #449 from ESP32Async/dependabot/github_actions/act…
…ions/cache-6 Bump actions/cache from 5 to 6
Configuration menu - View commit details
-
Copy full SHA for cf5c3b9 - Browse repository at this point
Copy the full SHA cf5c3b9View commit details -
fix(WebRequest): CWE-190/DoS fix and boundary-parsing refactor
Tighten multipart boundary parsing in _parseReqHeader(): - Replace String::charAt() inner loop with a raw C-string pointer and pre-computed length for faster, allocation-free scanning. - Add an early-exit upper bound on the scan loop so that positions where 'boundary=' cannot possibly fit are skipped entirely. - Replace the three-pass quoted-string extraction (find close-quote, substring, then unescape) with a single-pass approach that writes directly into _boundary using a raw pointer+length pair — no intermediate heap allocations and no C++17 dependency. - Enforce the RFC 2046 §5.1 70-character limit on boundary length in both token and quoted-string paths; abort with PARSE_REQ_FAIL on violation to prevent CWE-190 integer-overflow / DoS. - Replace strncmp length guard with a position-based early break that is clearer and avoids the redundant cast. - Fix ESP8266 build: String(const char*, size_t) is unavailable; use a 71-byte stack buffer + String(const char*) instead (#ifdef ESP8266). - Fix LibreTiny/C++14 build: remove std::string_view (C++17 only); replaced with plain const char* + size_t throughout. Ref: #445
Configuration menu - View commit details
-
Copy full SHA for 39390f4 - Browse repository at this point
Copy the full SHA 39390f4View commit details -
Use a token-based loop instead of a byte loop as the primary parser for multipart options. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for 55b1a44 - Browse repository at this point
Copy the full SHA 55b1a44View commit details -
fix(WebRequest): reject empty quoted-string boundary
willmmiles' parameter-loop refactor (65e128e) removed the final _boundary length safety net that existed after both extraction branches, relying on per-branch checks. However, the per-branch checks do not cover the empty quoted-string case: boundary="" closes immediately with _boundary still empty and falls through to _isMultipart = true without rejection. Downstream in EXPECT_BOUNDARY, an empty _boundary would cause --\r\n to be accepted as a valid boundary delimiter, reintroducing the CWE-190 / DoS condition this PR is meant to fix. Restore the final safety check (length == 0 || length > 70) with a comment explaining the empty-quoted-string gap that motivates it. Ref: #447 (comment)
Configuration menu - View commit details
-
Copy full SHA for 4a172a0 - Browse repository at this point
Copy the full SHA 4a172a0View commit details
Commits on Jun 25, 2026
-
Merge pull request #447 from ESP32Async/CWE-190
fix(WebRequest): CWE-190/DoS fix and boundary-parsing refactor
Configuration menu - View commit details
-
Copy full SHA for ef03828 - Browse repository at this point
Copy the full SHA ef03828View commit details
Commits on Jun 28, 2026
-
fix: NULL pointer dereference in multipart parser (GHSA-8m8p-vhxc-jmjw)
When the multipart parser matched '--<boundary>' inside file data, it freed _itemBuffer but left _itemIsFile = true. If the next byte was neither the closing '--' nor a clean '\r\n', the rewind logic in DASH3_OR_RETURN2 / EXPECT_FEED2 called itemWriteByte(), which dereferenced the now-NULL _itemBuffer via _handleUploadByte, causing a StoreProhibited crash on ESP32 (remote DoS, CWE-476 / CWE-672). Fix: - Reset _itemIsFile = false immediately after freeing _itemBuffer in BOUNDARY_OR_DATA, so the rewind logic writes to _itemValue (String) instead of the freed buffer. - Add a NULL guard in _handleUploadByte as defense-in-depth. Added test case 11 in MultiPart.ino to reproduce and verify the fix.
Configuration menu - View commit details
-
Copy full SHA for 4efbd35 - Browse repository at this point
Copy the full SHA 4efbd35View commit details -
Merge pull request #450 from ESP32Async/security/advisories/GHSA-8m8p…
…-vhxc-jmjw fix: NULL pointer dereference in multipart parser (GHSA-8m8p-vhxc-jmjw)
Configuration menu - View commit details
-
Copy full SHA for 21305e1 - Browse repository at this point
Copy the full SHA 21305e1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8995465 - Browse repository at this point
Copy the full SHA 8995465View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v3.11.1...v3.11.2