AGR-2026-103 — Challenge auth-param names are parsed case-sensitively
Last observed by the head-to-head audit at 2026-09-14T09:17:13.387847Z.
Audited heads
| Target |
Repository |
Commit |
Conformance |
Semantic review |
typescript |
wevm/mppx |
3c14a65a7ea5 |
Complete |
Reference |
python |
tempoxyz/pympp |
7988d1cda5c4 |
Complete |
Complete |
rust |
tempoxyz/mpp-rs |
d859a13d74ef |
Complete |
Complete |
go |
tempoxyz/mpp-go |
9fcf9a47c61b |
Complete |
Complete |
java |
stripe/mpp-java |
ca57f0998545 |
Complete |
Complete |
ruby |
stripe/mpp-rb |
3b9e2923c67b |
Complete |
Complete |
Finding
- Fingerprint:
semantic:challenge-parsing/case-insensitive-auth-parameter-names
- Source: semantic
- Affected SDKs:
python, rust
- Clean SDKs: none
- Not reported by semantic review:
go, java, ruby
- Canonical reference:
draft-ietf-httpauth-payment §5.1; RFC 9110 §11.2
- Severity: medium
- Confidence: high
Evidence
| SDK |
Canonical evidence |
SDK evidence |
Suggested test |
python |
parseAuthParams — Lowercases each parsed auth-parameter name before storage and duplicate detection. |
_parse_auth_params — Stores parameter names with their original casing; required-field lookup later uses lowercase keys. |
Parse a valid challenge with ID, Realm, Method, Intent, and Request parameter names and assert success; then add both realm and Realm and assert a duplicate-parameter error. |
rust |
parseAuthParams — Lowercases each auth-param name before storage and duplicate detection. |
parse_auth_params — Stores auth-param names with their original casing; parse_www_authenticate later retrieves only lowercase names. |
Parse a valid challenge whose required parameter names are ID, Realm, Method, Intent, and Request; assert it equals the lowercase form, then assert id=... plus ID=... is rejected as a duplicate. |
python: The canonical challenge parser normalizes auth-parameter names to lowercase and detects duplicates after normalization. The target retains original casing but subsequently looks up required parameters using lowercase names. A valid challenge using Realm, Method, or other differently cased parameter names is therefore rejected, while mixed-case duplicates can evade duplicate detection.
rust: HTTP authentication parameter names are case-insensitive. Canonical mppx normalizes every parsed name to lowercase, so fields such as ID, Realm, or Request work and differently cased duplicates are rejected. The Rust parser retains the original spelling and subsequently looks up lowercase keys. Consequently, an otherwise valid challenge using uppercase or mixed-case required parameter names is rejected as missing fields; differently cased duplicates can also evade duplicate detection.
Available /ag commands
Post a command as a new comment. Only configured maintainers can run these commands.
| Target |
Automation |
Status |
Pull request |
rust |
pr |
Queued |
— |
python |
pr |
Queued |
— |
Quick action
Use GitHub's copy button, then post this command as a comment:
| Command |
What it does |
/ag fix |
Opens or retries draft fixes for every affected PR-enabled SDK. |
/ag fix python |
Opens or retries the draft fix for python only. |
/ag fix rust |
Opens or retries the draft fix for rust only. |
/ag fix "instruction" |
Applies the instruction to affected fixes; recorded PRs also incorporate unresolved review feedback and failed CI. |
/ag status |
Reports the current state of linked remediation pull requests. |
AGR-2026-103 — Challenge auth-param names are parsed case-sensitively
Last observed by the head-to-head audit at
2026-09-14T09:17:13.387847Z.Audited heads
typescriptwevm/mppx3c14a65a7ea5pythontempoxyz/pympp7988d1cda5c4rusttempoxyz/mpp-rsd859a13d74efgotempoxyz/mpp-go9fcf9a47c61bjavastripe/mpp-javaca57f0998545rubystripe/mpp-rb3b9e2923c67bFinding
semantic:challenge-parsing/case-insensitive-auth-parameter-namespython,rustgo,java,rubydraft-ietf-httpauth-payment §5.1; RFC 9110 §11.2Evidence
pythonID,Realm,Method,Intent, andRequestparameter names and assert success; then add bothrealmandRealmand assert a duplicate-parameter error.rustID,Realm,Method,Intent, andRequest; assert it equals the lowercase form, then assertid=...plusID=...is rejected as a duplicate.python: The canonical challenge parser normalizes auth-parameter names to lowercase and detects duplicates after normalization. The target retains original casing but subsequently looks up required parameters using lowercase names. A valid challenge using
Realm,Method, or other differently cased parameter names is therefore rejected, while mixed-case duplicates can evade duplicate detection.rust: HTTP authentication parameter names are case-insensitive. Canonical mppx normalizes every parsed name to lowercase, so fields such as
ID,Realm, orRequestwork and differently cased duplicates are rejected. The Rust parser retains the original spelling and subsequently looks up lowercase keys. Consequently, an otherwise valid challenge using uppercase or mixed-case required parameter names is rejected as missing fields; differently cased duplicates can also evade duplicate detection.Available
/agcommandsPost a command as a new comment. Only configured maintainers can run these commands.
rustpythonQuick action
Use GitHub's copy button, then post this command as a comment:
/ag fix/ag fix pythonpythononly./ag fix rustrustonly./ag fix "instruction"/ag status