summaryrefslogtreecommitdiffstats
path: root/test/headers-crlf.js
diff options
context:
space:
mode:
Diffstat (limited to 'test/headers-crlf.js')
-rw-r--r--test/headers-crlf.js36
1 files changed, 36 insertions, 0 deletions
diff --git a/test/headers-crlf.js b/test/headers-crlf.js
new file mode 100644
index 0000000..b24fd39
--- /dev/null
+++ b/test/headers-crlf.js
@@ -0,0 +1,36 @@
+'use strict'
+
+const { test } = require('tap')
+const { Client } = require('..')
+const { createServer } = require('http')
+
+test('CRLF Injection in Nodejs ‘undici’ via host', (t) => {
+ t.plan(1)
+
+ const server = createServer(async (req, res) => {
+ res.end()
+ })
+ t.teardown(server.close.bind(server))
+
+ server.listen(0, async () => {
+ const client = new Client(`http://localhost:${server.address().port}`)
+ t.teardown(client.close.bind(client))
+
+ const unsanitizedContentTypeInput = '12 \r\n\r\naaa:aaa'
+
+ try {
+ const { body } = await client.request({
+ path: '/',
+ method: 'POST',
+ headers: {
+ 'content-type': 'application/json',
+ host: unsanitizedContentTypeInput
+ },
+ body: 'asd'
+ })
+ await body.dump()
+ } catch (err) {
+ t.same(err.code, 'UND_ERR_INVALID_ARG')
+ }
+ })
+})