Skip to content

fix(everything): reject HTTP error responses in gzip-file-as-resource - #4953

Open
kabishou11 wants to merge 1 commit into
modelcontextprotocol:mainfrom
kabishou11:fix/everything-gzip-http-status
Open

kabishou11 wants to merge 1 commit into
modelcontextprotocol:mainfrom
kabishou11:fix/everything-gzip-http-status

Conversation

@kabishou11

Copy link
Copy Markdown

Description

gzip-file-as-resource compresses whatever body the URL returns, including HTTP error pages. fetchSafely only checks that response.body exists and never looks at response.ok. A 404 or 500 response therefore comes back as a normal application/gzip resource whose contents are the server's error page.

This change checks response.ok before reading. If the response is not OK, it cancels the unread body and throws Failed to fetch <url>: status <code>, the same way the tool already reports other fetch failures.

Server Details

  • Server: everything
  • Changes to: tools (gzip-file-as-resource)

Motivation and Context

Before (local HTTP server serving 200 / 404 / 500):

PATH /ok.txt: SUCCESS decompressed="real file contents"
PATH /missing.txt: SUCCESS decompressed="error body for 404"
PATH /boom.txt: SUCCESS decompressed="error body for 500"

After:

PATH /ok.txt: SUCCESS decompressed="real file contents"
PATH /missing.txt: THREW Failed to fetch http://127.0.0.1:<port>/missing.txt: status 404
PATH /boom.txt: THREW Failed to fetch http://127.0.0.1:<port>/boom.txt: status 500

How Has This Been Tested?

  • New test should reject HTTP error responses instead of compressing the error page in src/everything/__tests__/tools.test.ts. It starts a local HTTP server on 127.0.0.1 and checks the 200, 404 and 500 cases. It fails on main and passes with this change.
  • vitest run in src/everything: 110 passed.
  • tsc --noEmit: clean.

Breaking Changes

None. Successful responses are handled exactly as before.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Protocol Documentation
  • My changes follows MCP security best practices
  • I have updated the server's README accordingly (not needed)
  • I have tested this with an LLM client
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have documented all environment variables and configuration options (none added)

Additional context

This is separate from the open SSRF and redirect PRs for this tool (#4498, #4622), which deal with which hosts may be fetched, not with the response status.

fetchSafely only checked that a body was present, so a 404 or 500 page
was compressed and returned as if it were the requested file.
@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0f6342f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant