Where: src/dispatch.rs:833 (format!(r#"{{\"error\":\"json: {e}\"}}"#)) and :901 (multipart error).
The error detail ({e}) is interpolated directly into a JSON string literal without escaping quotes/backslashes/control characters. If the underlying parser error message ever contains a " or other JSON-special character (plausible for some malformed multipart/JSON inputs), the resulting body is invalid JSON and could let a value spill into an unintended key.
Fix direction: build these error bodies via serde_json::json!/serde_json::to_string (as already done elsewhere in the file, e.g. send_internal_error) instead of format!.
Where:
src/dispatch.rs:833(format!(r#"{{\"error\":\"json: {e}\"}}"#)) and:901(multipart error).The error detail (
{e}) is interpolated directly into a JSON string literal without escaping quotes/backslashes/control characters. If the underlying parser error message ever contains a"or other JSON-special character (plausible for some malformed multipart/JSON inputs), the resulting body is invalid JSON and could let a value spill into an unintended key.Fix direction: build these error bodies via
serde_json::json!/serde_json::to_string(as already done elsewhere in the file, e.g.send_internal_error) instead offormat!.