Commit 5778c1261d for openssl.org

commit 5778c1261dc1b39d9758a33a0dd1c3035bad470d
Author: Bob Beck <beck@openssl.org>
Date:   Fri Sep 11 20:53:10 2026 -0600

    Build the proxy authorization string with asprintf

    Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
    Reviewed-by: Andrew Dinh <andrewd@openssl.org>
    Merge-date: Fri Oct  2 07:18:24 2026
    Merged-from: https://github.com/openssl/openssl/pull/31550

diff --git a/crypto/http/http_client.c b/crypto/http/http_client.c
index db0aaf6d8b..6cca340923 100644
--- a/crypto/http/http_client.c
+++ b/crypto/http/http_client.c
@@ -23,6 +23,7 @@
 #include <openssl/trace.h>
 #include "internal/sockets.h"
 #include "internal/common.h" /* for ossl_assert() */
+#include "internal/cryptlib.h" /* for ossl_asprintf() */

 #define HTTP_PREFIX "HTTP/"
 #define HTTP_VERSION_PATT "1." /* allow 1.x */
@@ -1500,25 +1501,19 @@ int OSSL_HTTP_proxy_connect(BIO *bio, const char *server, const char *port,

     /* Support for basic (base64) proxy authentication */
     if (proxyuser != NULL) {
-        size_t len = strlen(proxyuser) + 1;
-        char *proxyauth, *proxyauthenc = NULL;
+        char *proxyauth = NULL, *proxyauthenc = NULL;
+        int len;

-        if (proxypass != NULL)
-            len += strlen(proxypass);
-        proxyauth = OPENSSL_malloc(len + 1);
-        if (proxyauth == NULL)
+        len = ossl_asprintf(&proxyauth, "%s:%s", proxyuser,
+            proxypass != NULL ? proxypass : "");
+        if (len < 0)
             goto end;
-        if (snprintf(proxyauth, len + 1, "%s:%s", proxyuser,
-                proxypass != NULL ? proxypass : "")
-            != (int)len)
-            goto proxy_end;
-        proxyauthenc = base64encode(proxyauth, len);
+        proxyauthenc = base64encode(proxyauth, (size_t)len);
         if (proxyauthenc != NULL) {
             BIO_printf(fbio, "Proxy-Authorization: Basic %s\r\n", proxyauthenc);
             OPENSSL_clear_free(proxyauthenc, strlen(proxyauthenc));
         }
-    proxy_end:
-        OPENSSL_clear_free(proxyauth, len);
+        OPENSSL_clear_free(proxyauth, (size_t)len);
         if (proxyauthenc == NULL)
             goto end;
     }