Commit 5faeafd69f for bind
commit 5faeafd69f9b0a17d67f6ef5a277bbc1da1c9430
Author: Mark Andrews <marka@isc.org>
Date: Tue Sep 29 11:59:55 2026 +1000
DoH client Content-Type validation accepted invalid values
The Content-Type validation accepted any value that started with
application/dns-message. This has been fixed.
diff --git a/lib/isc/netmgr/http.c b/lib/isc/netmgr/http.c
index 22a5843454..daa5232107 100644
--- a/lib/isc/netmgr/http.c
+++ b/lib/isc/netmgr/http.c
@@ -823,11 +823,8 @@ static bool
client_handle_content_type_header(http_cstream_t *cstream, const uint8_t *value,
const size_t valuelen) {
const char type_dns_message[] = DNS_MEDIA_TYPE;
- const size_t len = sizeof(type_dns_message) - 1;
- UNUSED(valuelen);
-
- if (strncasecmp((const char *)value, type_dns_message, len) == 0) {
+ if (HEADER_MATCH(type_dns_message, value, valuelen)) {
cstream->response_status.content_type_valid = true;
return true;
}