What changed, and why it matters
This is a one-line bug fix in Monero's embedded HTTP protocol handler. The code was accidentally passing the major HTTP version number twice to a parsing function, instead of passing both the major and minor version numbers. The fix makes the parser receive the correct minor version number. This is clearly a bug, but from the diff alone it is hard to tell whether it has any practical security consequence.
Treat as a low-confidence, low-severity bug fix. Review the implementation of analize_http_method() and any callers of m_http_ver_lo to determine whether the duplicated major version could have caused request misclassification, version downgrade issues, or parser state errors. No immediate emergency action is warranted based solely on this diff.
Security signals we found
Bug fix in network protocol parsing code
Incorrect argument duplication in security-relevant parsing function
HTTP version handling correction
Evidence from the diff
In contrib/epee/include/net/http_protocol_handler.inl, the call to analize_http_method() was passing m_query_info.m_http_ver_hi as both the third and fourth arguments. The fourth argument is meant to be the minor HTTP version (m_query_info.m_http_ver_lo). The patch corrects the duplicated argument to m_query_info.m_http_ver_lo. This fixes HTTP version parsing logic, but the diff does not show what analize_http_method() does with the minor version, so downstream effects are speculative.
Changed components
contrib/epee/include/net/http_protocol_handler.inlHTTP protocol parser (analize_http_method)Inspect captured patch +1 / −1
diff --git a/contrib/epee/include/net/http_protocol_handler.inl b/contrib/epee/include/net/http_protocol_handler.inl
index f66c316..0db5c0c 100644
--- a/contrib/epee/include/net/http_protocol_handler.inl
+++ b/contrib/epee/include/net/http_protocol_handler.inl
@@ -404,7 +404,7 @@ namespace net_utils
boost::smatch result;
if(boost::regex_search(m_cache, result, rexp_match_command_line, boost::match_default) && result[0].matched)
{
- if (!analize_http_method(result, m_query_info.m_http_method, m_query_info.m_http_ver_hi, m_query_info.m_http_ver_hi))
+ if (!analize_http_method(result, m_query_info.m_http_method, m_query_info.m_http_ver_hi, m_query_info.m_http_ver_lo))
{
m_state = http_state_error;
MERROR("Failed to analyze method");
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.