epee: parse HTTP methods case-sensitively
What changed, and why it matters
This commit tightens how the Monero software reads incoming HTTP requests by only accepting method names like GET and POST when written in uppercase. Previously, lowercase or mixed-case versions such as 'get' or 'Post' were also accepted. The change makes the parser follow the HTTP standard more strictly, which can help block unusual requests that might be used to bypass security checks or confuse proxies and firewalls.
Treat as a hardening fix rather than a confirmed vulnerability. Review whether any HTTP-RPC, REST, or administrative endpoints in Monero rely on exact method-string comparisons that could have been bypassed by case variants. Monitor for related follow-up commits, security advisories, or CVEs. No immediate emergency response is indicated by the diff alone.
Security signals we found
HTTP request-line parsing made case-sensitive for method tokens
Removes regex case-insensitive flag from HTTP command-line matcher
Aligns parser with RFC 7230 method-token case-sensitivity requirement
Potential request-smuggling or WAF/proxy bypass signal, but no exploit demonstrated in commit
Evidence from the diff
The patch removes the boost::regex::icase flag from the regular expression that parses the HTTP request line in contrib/epee/include/net/http_protocol_handler.inl. Without the case-insensitive flag, only uppercase methods (OPTIONS, GET, HEAD, POST, PUT, DELETE, TRACE) are accepted. HTTP/1.1 RFC 7230 specifies that method tokens are case-sensitive and must be uppercase, so this change aligns the parser with the standard and prevents non-compliant method spellings from reaching downstream logic. The actual security impact depends on whether any access-control or routing decisions elsewhere in the code rely on exact method-string matching and could be bypassed by case variation.
Changed components
contrib/epee/include/net/http_protocol_handler.inlsimple_http_connection_handler::handle_invoke_query_line()Inspect captured patch +1 / −1
diff --git a/contrib/epee/include/net/http_protocol_handler.inl b/contrib/epee/include/net/http_protocol_handler.inl
index a908c46..cf0d729 100644
--- a/contrib/epee/include/net/http_protocol_handler.inl
+++ b/contrib/epee/include/net/http_protocol_handler.inl
@@ -400,7 +400,7 @@ namespace net_utils
template<class t_connection_context>
bool simple_http_connection_handler<t_connection_context>::handle_invoke_query_line()
{
- static const boost::regex rexp_match_command_line("^(((OPTIONS)|(GET)|(HEAD)|(POST)|(PUT)|(DELETE)|(TRACE)) (\\S+) HTTP/(\\d+)\\.(\\d+))\r?\n", boost::regex::icase | boost::regex::normal);
+ static const boost::regex rexp_match_command_line("^(((OPTIONS)|(GET)|(HEAD)|(POST)|(PUT)|(DELETE)|(TRACE)) (\\S+) HTTP/(\\d+)\\.(\\d+))\r?\n", boost::regex::normal);
// 123 4 5 6 7 8 9 10 11 12
//size_t match_len = 0;
boost::smatch result;
Why this scored 39/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.