This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 11.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 1b2ad67e5ff4cf9ea181ef7cd749dd7681554312
Author: opencode <[email protected]>
AuthorDate: Wed Sep 30 11:12:02 2026 +0200

    Fall back to the raw trimmed filename value in 
ApplicationPart.getSubmittedFileName() when HttpParser.unquote() rejects an 
invalid quoted-string, keeping the result consistent with the file-vs-field 
classification performed by FileUploadBase.getFileName() for malformed 
Content-Disposition headers
---
 java/org/apache/catalina/core/ApplicationPart.java |  7 +++-
 .../apache/catalina/core/TestApplicationPart.java  | 44 ++++++++++++++++++++++
 2 files changed, 50 insertions(+), 1 deletion(-)

diff --git a/java/org/apache/catalina/core/ApplicationPart.java 
b/java/org/apache/catalina/core/ApplicationPart.java
index 95a7167b19..db523e22cd 100644
--- a/java/org/apache/catalina/core/ApplicationPart.java
+++ b/java/org/apache/catalina/core/ApplicationPart.java
@@ -161,7 +161,12 @@ public class ApplicationPart implements Part {
                         // RFC 6266. This is either a token or a quoted-string
                         if (fileName.indexOf('\\') > -1) {
                             // This is a quoted-string
-                            fileName = HttpParser.unquote(fileName.trim());
+                            String unquoted = 
HttpParser.unquote(fileName.trim());
+                            // If the quoted-string was invalid (e.g. ended
+                            // with a backslash) fall back to the raw value to
+                            // remain consistent with the classifier used by
+                            // the multipart parser 
(FileUploadBase.getFileName)
+                            fileName = unquoted != null ? unquoted : 
fileName.trim();
                         } else {
                             // This is a token
                             fileName = fileName.trim();
diff --git a/test/org/apache/catalina/core/TestApplicationPart.java 
b/test/org/apache/catalina/core/TestApplicationPart.java
new file mode 100644
index 0000000000..6b278a1216
--- /dev/null
+++ b/test/org/apache/catalina/core/TestApplicationPart.java
@@ -0,0 +1,44 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.catalina.core;
+
+import org.junit.Assert;
+import org.junit.Test;
+
+import org.apache.tomcat.util.http.fileupload.disk.DiskFileItem;
+import org.apache.tomcat.util.http.fileupload.util.FileItemHeadersImpl;
+
+public class TestApplicationPart {
+
+    private static ApplicationPart createPart(String contentDisposition) {
+        DiskFileItem fileItem = new DiskFileItem("field", "text/plain", false, 
"name", 102400, null);
+        FileItemHeadersImpl headers = new FileItemHeadersImpl();
+        headers.addHeader("Content-Disposition", contentDisposition);
+        fileItem.setHeaders(headers);
+        return new ApplicationPart(fileItem, null);
+    }
+
+
+    @Test
+    public void testSubmittedFileNameUnterminatedQuotedString() {
+        // An escaped closing quote makes the quoted-string invalid.
+        // getSubmittedFileName() must not diverge (return null) from the
+        // classifier used by the multipart parser (which yields "abc\").
+        ApplicationPart part = createPart("form-data; name=\"x\"; 
filename=\"abc\\\"");
+        Assert.assertEquals("abc\\", part.getSubmittedFileName());
+    }
+}


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to