From d1d84ed9af1f2fb26614e35842949a8fce3b124f Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Mon, 28 Sep 2026 20:36:28 +0200 Subject: [PATCH] Fix Flawfinder: format the BSON element type without snprintf Moving the report of an unsupported BSON element type into skip_unsupported_bson_element() moved its snprintf() call, which Flawfinder then reported as a new CWE-134 finding. The two hexadecimal digits are now computed directly; the message is unchanged. Signed-off-by: Niels Lohmann --- include/nlohmann/detail/input/binary_reader.hpp | 10 +++++++--- single_include/nlohmann/json.hpp | 10 +++++++--- 2 files changed, 14 insertions(+), 6 deletions(-) diff --git a/include/nlohmann/detail/input/binary_reader.hpp b/include/nlohmann/detail/input/binary_reader.hpp index 711038c3a..35cfb16b5 100644 --- a/include/nlohmann/detail/input/binary_reader.hpp +++ b/include/nlohmann/detail/input/binary_reader.hpp @@ -401,9 +401,13 @@ class binary_reader */ bool skip_unsupported_bson_element(const char_int_type element_type, const std::size_t element_type_parse_position) { - std::array cr{{}}; - static_cast((std::snprintf)(cr.data(), cr.size(), "%.2hhX", static_cast(element_type))); // NOLINT(cppcoreguidelines-pro-type-vararg,hicpp-vararg) - const std::string cr_str{cr.data()}; + // the type as two uppercase hexadecimal digits, without a format string + const auto type_byte = static_cast(static_cast(element_type)); + const auto hex_digit = [](const unsigned int digit) + { + return static_cast(digit < 10 ? '0' + digit : 'A' + (digit - 10)); + }; + const std::string cr_str{hex_digit(type_byte >> 4u), hex_digit(type_byte & 0x0Fu)}; const auto error = parse_error::create(114, element_type_parse_position, concat("Unsupported BSON record type 0x", cr_str), nullptr); // the number of bytes to skip, -1 if the value is read differently, or diff --git a/single_include/nlohmann/json.hpp b/single_include/nlohmann/json.hpp index a90aa2562..5618dff45 100644 --- a/single_include/nlohmann/json.hpp +++ b/single_include/nlohmann/json.hpp @@ -13795,9 +13795,13 @@ class binary_reader */ bool skip_unsupported_bson_element(const char_int_type element_type, const std::size_t element_type_parse_position) { - std::array cr{{}}; - static_cast((std::snprintf)(cr.data(), cr.size(), "%.2hhX", static_cast(element_type))); // NOLINT(cppcoreguidelines-pro-type-vararg,hicpp-vararg) - const std::string cr_str{cr.data()}; + // the type as two uppercase hexadecimal digits, without a format string + const auto type_byte = static_cast(static_cast(element_type)); + const auto hex_digit = [](const unsigned int digit) + { + return static_cast(digit < 10 ? '0' + digit : 'A' + (digit - 10)); + }; + const std::string cr_str{hex_digit(type_byte >> 4u), hex_digit(type_byte & 0x0Fu)}; const auto error = parse_error::create(114, element_type_parse_position, concat("Unsupported BSON record type 0x", cr_str), nullptr); // the number of bytes to skip, -1 if the value is read differently, or