http-rs / http-rs/async-h1

Header DoS (surf#298)

Open
#186 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Rust
Stars
166
Forks
49
PR merge metrics
No merged PRs in 30d

Description

this is a mirror issue for https://github.com/http-rs/surf/issues/298

> surf will use an unbounded amount of memory if the server sends a single infinitely large header. surf has some DoS prevention (see #289) but it only protects from an infinite amount of headers, not from a single infinitely large header.

> You can reproduce the issue by running the following in Linux console and then connecting to localhost:8080 with surf:

> `( echo -e "HTTP/1.1 200 OK\r"; echo -n "Huge-header: "; yes A | tr -d '\n' ) | nc -l localhost 8080`

> Tested using this code for surf. You can inspect the Cargo.lock to know the exact dependency versions.

> I've only tested the async-h1 backend; I don't know if the other backends are affected.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the issue with the Linux console command in the report, then inspect the Cargo.lock versions and trace header parsing in the async-h1 backend. The work is done when a single unbounded header cannot consume unlimited memory and the affected behavior is covered by a regression check.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
api, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.