Skip to content

feat(920640): add rule to enforce content-type if there is body#4406

Merged
fzipi merged 2 commits into
mainfrom
feat/add-rule-check-content-type-if-body
Jan 16, 2026
Merged

feat(920640): add rule to enforce content-type if there is body#4406
fzipi merged 2 commits into
mainfrom
feat/add-rule-check-content-type-if-body

Conversation

@fzipi
Copy link
Copy Markdown
Member

@fzipi fzipi commented Jan 15, 2026

what

  • add new rule to enforce content-type if there is body
  • update 'msg' on rule 920340 to be more accurate

why

  • attacks will try to bypass processor unless rule 900010 is enabled
  • rule 900010 can be prone to false positives

Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
@fzipi fzipi requested a review from a team January 15, 2026 22:33
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Jan 15, 2026

📊 Quantitative test results for language: eng, year: 2023, size: 10K, paranoia level: 1:
🚀 Quantitative testing did not detect new false positives

Copy link
Copy Markdown
Member

@EsadCetiner EsadCetiner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

.

Comment thread rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
@fzipi fzipi requested review from EsadCetiner and airween January 16, 2026 12:47
@fzipi fzipi added this pull request to the merge queue Jan 16, 2026
Merged via the queue into main with commit 225eceb Jan 16, 2026
8 checks passed
@fzipi fzipi deleted the feat/add-rule-check-content-type-if-body branch January 16, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants