reject leading zeros in strict-mode number parsing

This commit is contained in:
Javid Khan
2026-07-28 13:27:25 +05:30
parent 1bd2e4b3ef
commit ff18c75286
3 changed files with 33 additions and 7 deletions
+16 -6
View File
@@ -1043,6 +1043,22 @@ struct json_object *json_tokener_parse_ex(struct json_tokener *tok, const char *
tok->st_pos = 0;
goto redo_char;
}
if (tok->flags & JSON_TOKENER_STRICT)
{
/* RFC 8259 forbids leading zeros in the integer part:
* a '0' may only be followed by '.', 'e'/'E' or the end
* of the number, so "01", "00" and "-0123" are invalid
* while "0", "-0" and "0.5" remain valid.
*/
const char *num = tok->pb->buf;
if (*num == '-')
num++;
if (num[0] == '0' && num[1] >= '0' && num[1] <= '9')
{
tok->err = json_tokener_error_parse_number;
goto out;
}
}
if (tok->is_double && !(tok->flags & JSON_TOKENER_STRICT))
{
/* Trim some chars off the end, to allow things
@@ -1087,12 +1103,6 @@ struct json_object *json_tokener_parse_ex(struct json_tokener *tok, const char *
tok->err = json_tokener_error_parse_number;
goto out;
}
if (numuint64 && tok->pb->buf[0] == '0' &&
(tok->flags & JSON_TOKENER_STRICT))
{
tok->err = json_tokener_error_parse_number;
goto out;
}
if (numuint64 <= INT64_MAX)
{
num64 = (uint64_t)numuint64;