Skip to content

h3: only accept WEBTRANSPORT_STREAM as the first frame - #653

Closed
cpruijsen wants to merge 1 commit into
aiortc:mainfrom
cpruijsen:fix/issue-638
Closed

cpruijsen wants to merge 1 commit into
aiortc:mainfrom
cpruijsen:fix/issue-638

Conversation

@cpruijsen

Copy link
Copy Markdown

A WEBTRANSPORT_STREAM frame (0x41) is accepted on a CONNECT stream without validation, so seven
bytes on that stream turn the control channel into a WebTransport data stream. h3/connection.py
then fires WebTransportStreamDataReceived with stream_id=0, which is a stream the application
never agreed to treat as data. It was found by fuzzing, and the sequence is trivial to send.

The frame is only legal at the start of a stream, where it declares what the stream is. Arriving
after the stream has already carried a frame, it is reinterpreting a stream mid-flight, which the
spec does not allow.

Streams now track received_frame, and a WEBTRANSPORT_STREAM on a stream that has already received
one raises FrameError, a new ProtocolError carrying H3_FRAME_ERROR. That is the code the spec
assigns to a frame that is invalid in its position, so the peer is told what was wrong rather than
seeing a generic failure, and the connection closes instead of the application receiving data on its
control channel.

Tests cover the reported byte sequence and a legitimate WebTransport stream, so the guard cannot pass
by refusing both.

Fixes #638

Per draft-ietf-webtrans-http3 section 4.3, a WEBTRANSPORT_STREAM frame
is only allowed as the very first frame of a request stream. Receiving
it on a stream which is already in use - such as a CONNECT stream - or
after another frame must be treated as a connection error of type
H3_FRAME_ERROR.
@cpruijsen

Copy link
Copy Markdown
Author

Closing this one. Not taking it further.

@cpruijsen cpruijsen closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

spec violation: WEBTRANSPORT_STREAM (0x41) accepted on CONNECT stream without validation

1 participant