A06: cap RPC request bodies and shrink the import decompression limit #11
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#11
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two related resource-exhaustion gaps:
connect.WithReadMaxBytesanywhere (internal/server/server.go). Connect buffers whole messages, so an unauthenticated POST toLoginwith a huge body is a pre-auth memory-exhaustion vector. Only the Read/Write timeouts bound it, and h2c multiplexing erodes that.internal/services/system/import.go:29,io.ReadAllat:197-205). A few-MB gzip bomb legally expands to 1 GiB plus a JSON-parse copy, against a 256Mi pod limit (values.cue:80). The caller is admin — or anonymous during the setup window. The code comment itself says family archives are megabytes.Fix
connect.WithReadMaxBytesto the handler options (a few MiB covers every legitimate RPC except import).maxImportBytesto 64-128 MiB.Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.