Skip to content

Managed HttpListener accepts whitespace around request header names #132128

Description

@iremyux

Description

The managed HttpListener implementation normalizes malformed request header names by trimming them:

string name = header.AsSpan(0, colon).Trim().ToString();

HTTP requires the field name to be immediately followed by : . A server must reject request messages containing whitespace between the field name and colon with 400 Bad Request. The managed implementation should validate the field name without trimming it. Optional ASCII spaces and tabs around the field value should continue to be removed.

Tests should cover valid headers and malformed names containing leading whitespace or whitespace before the colon.

Reproduction Steps

Send a request containing header : value.

Expected behavior

It should be rejected with 400 Bad Request.

Actual behavior

The request reaches the application with the header normalized to header .

Regression?

No response

Known Workarounds

No response

Configuration

No response

Other information

No response

Activity

  1. self-assigned this
    on Aug 11, 2026
  2. dotnet-policy-service commented on Aug 11, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @karelz, @dotnet/ncl
    See info in area-owners.md if you want to be subscribed.

  3. added this to the 12.0.0 milestone on Aug 11, 2026
  4. dotnet-policy-service commented on Aug 11, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @karelz, @dotnet/ncl
    See info in area-owners.md if you want to be subscribed.

  5. added a commit that references this issue on Aug 14, 2026
    6bb4060
  6. modified the milestones: 12.0.0, 11.0.0 on Aug 14, 2026
  7. locked and limited conversation to collaborators on Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions