Sitelet https://github.com/ESP32Async/ESPAsyncWebServer/compare/v3.11.1...v3.11.2
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: ESP32Async/ESPAsyncWebServer
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v3.11.1
Choose a base ref
...
head repository: ESP32Async/ESPAsyncWebServer
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v3.11.2
Choose a head ref
  • 15 commits
  • 24 files changed
  • 6 contributors

Commits on Jun 8, 2026

  1. Configuration menu
    Copy the full SHA
    88d5412 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    dd2e9a6 View commit details
    Browse the repository at this point in the history

Commits on Jun 9, 2026

  1. Configuration menu
    Copy the full SHA
    6c42da6 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #446 from MitchBradley/FixFS

    For examples/arduino_emulator, removed dependency on arduino-esp32
    mathieucarbou authored Jun 9, 2026
    Configuration menu
    Copy the full SHA
    3469e82 View commit details
    Browse the repository at this point in the history

Commits on Jun 19, 2026

  1. Bump actions/checkout from 6 to 7

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
    - [Release notes](https://github.com/actions/checkout/releases)
    - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
    - [Commits](actions/checkout@v6...v7)
    
    ---
    updated-dependencies:
    - dependency-name: actions/checkout
      dependency-version: '7'
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    b61a94e View commit details
    Browse the repository at this point in the history
  2. Merge pull request #448 from ESP32Async/dependabot/github_actions/act…

    …ions/checkout-7
    
    Bump actions/checkout from 6 to 7
    mathieucarbou authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    e345b1e View commit details
    Browse the repository at this point in the history

Commits on Jun 24, 2026

  1. Bump actions/cache from 5 to 6

    Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
    - [Release notes](https://github.com/actions/cache/releases)
    - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
    - [Commits](actions/cache@v5...v6)
    
    ---
    updated-dependencies:
    - dependency-name: actions/cache
      dependency-version: '6'
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Jun 24, 2026
    Configuration menu
    Copy the full SHA
    db8e7b4 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #449 from ESP32Async/dependabot/github_actions/act…

    …ions/cache-6
    
    Bump actions/cache from 5 to 6
    mathieucarbou authored Jun 24, 2026
    Configuration menu
    Copy the full SHA
    cf5c3b9 View commit details
    Browse the repository at this point in the history
  3. fix(WebRequest): CWE-190/DoS fix and boundary-parsing refactor

    Tighten multipart boundary parsing in _parseReqHeader():
    
    - Replace String::charAt() inner loop with a raw C-string pointer and
      pre-computed length for faster, allocation-free scanning.
    - Add an early-exit upper bound on the scan loop so that positions
      where 'boundary=' cannot possibly fit are skipped entirely.
    - Replace the three-pass quoted-string extraction (find close-quote,
      substring, then unescape) with a single-pass approach that writes
      directly into _boundary using a raw pointer+length pair — no
      intermediate heap allocations and no C++17 dependency.
    - Enforce the RFC 2046 §5.1 70-character limit on boundary length in
      both token and quoted-string paths; abort with PARSE_REQ_FAIL on
      violation to prevent CWE-190 integer-overflow / DoS.
    - Replace strncmp length guard with a position-based early break that
      is clearer and avoids the redundant cast.
    - Fix ESP8266 build: String(const char*, size_t) is unavailable; use
      a 71-byte stack buffer + String(const char*) instead (#ifdef ESP8266).
    - Fix LibreTiny/C++14 build: remove std::string_view (C++17 only);
      replaced with plain const char* + size_t throughout.
    
    Ref: #445
    mathieucarbou committed Jun 24, 2026
    Configuration menu
    Copy the full SHA
    39390f4 View commit details
    Browse the repository at this point in the history
  4. Tighten up boundary parsing

    Use a token-based loop instead of a byte loop as the primary parser for
    multipart options.
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    2 people authored and mathieucarbou committed Jun 24, 2026
    Configuration menu
    Copy the full SHA
    55b1a44 View commit details
    Browse the repository at this point in the history
  5. fix(WebRequest): reject empty quoted-string boundary

    willmmiles' parameter-loop refactor (65e128e) removed the final
    _boundary length safety net that existed after both extraction
    branches, relying on per-branch checks.  However, the per-branch
    checks do not cover the empty quoted-string case: boundary=""
    closes immediately with _boundary still empty and falls through to
    _isMultipart = true without rejection.
    
    Downstream in EXPECT_BOUNDARY, an empty _boundary would cause
    --\r\n to be accepted as a valid boundary delimiter, reintroducing
    the CWE-190 / DoS condition this PR is meant to fix.
    
    Restore the final safety check (length == 0 || length > 70) with a
    comment explaining the empty-quoted-string gap that motivates it.
    
    Ref: #447 (comment)
    mathieucarbou committed Jun 24, 2026
    Configuration menu
    Copy the full SHA
    4a172a0 View commit details
    Browse the repository at this point in the history

Commits on Jun 25, 2026

  1. Merge pull request #447 from ESP32Async/CWE-190

    fix(WebRequest): CWE-190/DoS fix and boundary-parsing refactor
    mathieucarbou authored Jun 25, 2026
    Configuration menu
    Copy the full SHA
    ef03828 View commit details
    Browse the repository at this point in the history

Commits on Jun 28, 2026

  1. fix: NULL pointer dereference in multipart parser (GHSA-8m8p-vhxc-jmjw)

    When the multipart parser matched '--<boundary>' inside file data, it
    freed _itemBuffer but left _itemIsFile = true.  If the next byte was
    neither the closing '--' nor a clean '\r\n', the rewind logic in
    DASH3_OR_RETURN2 / EXPECT_FEED2 called itemWriteByte(), which dereferenced
    the now-NULL _itemBuffer via _handleUploadByte, causing a StoreProhibited
    crash on ESP32 (remote DoS, CWE-476 / CWE-672).
    
    Fix:
    - Reset _itemIsFile = false immediately after freeing _itemBuffer in
      BOUNDARY_OR_DATA, so the rewind logic writes to _itemValue (String)
      instead of the freed buffer.
    - Add a NULL guard in _handleUploadByte as defense-in-depth.
    
    Added test case 11 in MultiPart.ino to reproduce and verify the fix.
    mathieucarbou committed Jun 28, 2026
    Configuration menu
    Copy the full SHA
    4efbd35 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #450 from ESP32Async/security/advisories/GHSA-8m8p…

    …-vhxc-jmjw
    
    fix: NULL pointer dereference in multipart parser (GHSA-8m8p-vhxc-jmjw)
    mathieucarbou authored Jun 28, 2026
    Configuration menu
    Copy the full SHA
    21305e1 View commit details
    Browse the repository at this point in the history
  3. v3.11.2

    mathieucarbou committed Jun 28, 2026
    Configuration menu
    Copy the full SHA
    8995465 View commit details
    Browse the repository at this point in the history
Loading