Header DoS (surf#298)
- Dominant language
- Rust
- Stars
- 166
- Forks
- 49
- PR merge metrics
- No merged PRs in 30d
Description
this is a mirror issue for https://github.com/http-rs/surf/issues/298
> surf will use an unbounded amount of memory if the server sends a single infinitely large header. surf has some DoS prevention (see #289) but it only protects from an infinite amount of headers, not from a single infinitely large header.
> You can reproduce the issue by running the following in Linux console and then connecting to localhost:8080 with surf:
> `( echo -e "HTTP/1.1 200 OK\r"; echo -n "Huge-header: "; yes A | tr -d '\n' ) | nc -l localhost 8080`
> Tested using this code for surf. You can inspect the Cargo.lock to know the exact dependency versions.
> I've only tested the async-h1 backend; I don't know if the other backends are affected.
Contributor guide
Research direction
Start by reproducing the issue with the Linux console command in the report, then inspect the Cargo.lock versions and trace header parsing in the async-h1 backend. The work is done when a single unbounded header cannot consume unlimited memory and the affected behavior is covered by a regression check.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- api, backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100