Skip to content

Conversation

@oetr
Copy link
Contributor

@oetr oetr commented Feb 10, 2026

org.apache.commons.imaging.formats.jpeg.JpegImageParser::getBufferedImage can open arbitrary files by design. File path traversal is not an issue here.

org.apache.commons.imaging.formats.jpeg.JpegImageParser::getBufferedImage
can open arbitrary files by design. File path traversal is not an
issue here.
Copilot AI review requested due to automatic review settings February 10, 2026 10:00
@oetr oetr requested a review from a team February 10, 2026 10:02
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Disables Jazzer’s FilePathTraversal sanitizer for the JpegImageParserAutofuzz test, since org.apache.commons.imaging.formats.jpeg.JpegImageParser::getBufferedImage is expected to open files and the sanitizer would flag that behavior.

Changes:

  • Add --disabled_hooks=com.code_intelligence.jazzer.sanitizers.FilePathTraversal to the JpegImageParserAutofuzz fuzz test arguments.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Contributor

@simonresch simonresch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@simonresch simonresch merged commit 9d542b9 into main Feb 10, 2026
15 checks passed
@simonresch simonresch deleted the chore-disable-sanitizer branch February 10, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants