Aias00 opened a new issue, #6633:
URL: https://github.com/apache/shenyu/issues/6633

   - Severity: High
   - Location:
   
`shenyu-plugin/shenyu-plugin-modify-response/src/main/java/org/apache/shenyu/plugin/modify/response/ModifyResponsePlugin.java:98-107`
 (`writeWith` always calls `modifyBody(bytes)`), `:160` (`modifyBody(String)` 
unconditionally calls `JsonPath.parse(jsonValue)`)
   - 
   Description:
   `writeWith` (line 98-107) always calls `modifyBody(bytes)`. 
`modifyBody(String)` (line 160) unconditionally executes `DocumentContext 
context = JsonPath.parse(jsonValue);` **before** and **regardless of** whether 
any `addBodyKeys`/`replaceBodyKeys`/`removeBodyKeys` are configured. The 
body-key branches at lines 161-169 are conditional, but the parse is not. If 
the matched route returns a non-JSON body (binary/image, HTML, plain text, 
CSS/JS, or an empty 204 body), `JsonPath.parse` throws `InvalidJsonException`. 
The catch at line 153-156 wraps it into a `ShenyuException`, producing a 500 
instead of passing the response through.
   - 
   Impact:
   A header-only ModifyResponse rule (only 
`addHeaders`/`setHeaders`/`replaceHeaderKeys`/`removeHeaderKeys`/`statusCode`) 
applied to any non-JSON response corrupts valid responses with a 500.
   - 
   Suggested fix:
   In `modifyBody(String)`, return the body unchanged when `addBodyKeys`, 
`replaceBodyKeys`, and `removeBodyKeys` are all empty, skipping 
`JsonPath.parse` entirely.
   - 
   Confidence: High
   - Related existing: #6510 is the `replaceHeaderKeys` name-vs-value bug in 
`modifyResponseHeadersAndStatus`; this is a separate body-parsing bug.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to