A06: cap RPC request bodies and shrink the import decompression limit #11

Closed
opened 2026-08-13 09:35:03 +00:00 by nalum · 0 comments
Owner

Two related resource-exhaustion gaps:

  1. No connect.WithReadMaxBytes anywhere (internal/server/server.go). Connect buffers whole messages, so an unauthenticated POST to Login with a huge body is a pre-auth memory-exhaustion vector. Only the Read/Write timeouts bound it, and h2c multiplexing erodes that.
  2. Import decompression cap is 1 GiB in RAM (internal/services/system/import.go:29, io.ReadAll at :197-205). A few-MB gzip bomb legally expands to 1 GiB plus a JSON-parse copy, against a 256Mi pod limit (values.cue:80). The caller is admin — or anonymous during the setup window. The code comment itself says family archives are megabytes.

Fix

  • Add connect.WithReadMaxBytes to the handler options (a few MiB covers every legitimate RPC except import).
  • Give import its own larger ceiling and drop maxImportBytes to 64-128 MiB.

Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

Two related resource-exhaustion gaps: 1. **No `connect.WithReadMaxBytes` anywhere** (`internal/server/server.go`). Connect buffers whole messages, so an unauthenticated POST to `Login` with a huge body is a pre-auth memory-exhaustion vector. Only the Read/Write timeouts bound it, and h2c multiplexing erodes that. 2. **Import decompression cap is 1 GiB in RAM** (`internal/services/system/import.go:29`, `io.ReadAll` at `:197-205`). A few-MB gzip bomb legally expands to 1 GiB plus a JSON-parse copy, against a 256Mi pod limit (`values.cue:80`). The caller is admin — or anonymous during the setup window. The code comment itself says family archives are megabytes. **Fix** - Add `connect.WithReadMaxBytes` to the handler options (a few MiB covers every legitimate RPC except import). - Give import its own larger ceiling and drop `maxImportBytes` to 64-128 MiB. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:46 +00:00
nalum closed this issue 2026-08-13 11:41:01 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#11
No description provided.