Skip to content

fix: reject oversized body via Content-Length before reading it - #228

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue-206-body-limit-before-read
Sep 29, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue-206-body-limit-before-read

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Problem

Granian's protocol() reads the entire request body into memory in one shot. OXYROUTE_MAX_BODY_BYTES was only checked after that read (and after a second copy into PooledBuffer), so a client sending a multi-GB body forces that full allocation before being rejected — trivial memory-exhaustion DoS regardless of the configured limit.

Fix

Check the request's declared Content-Length against the limit before awaiting protocol(), and return 413 immediately if it's too large. Bodies without Content-Length (chunked transfer-encoding) still fall through to the existing post-read check, so this closes the common/most exploitable case (an attacker declaring an oversized body) without buffering it first.

Testing

cargo build --lib and maturin develop --release succeed. tests/test_form_body.py::test_payload_too_large_413, tests/test_json_body.py, tests/test_db_query.py pass.

Closes #206

…g it

Granian's protocol() reads the entire request body into memory in one
shot; the OXYROUTE_MAX_BODY_BYTES check ran only after that read and
after a second copy into PooledBuffer, so a client could force a
multi-GB allocation per request regardless of the configured limit.

Check the declared Content-Length against the limit before awaiting
protocol() and reject with 413 up front. Bodies without a
Content-Length (chunked transfer-encoding) still fall through to the
existing post-read check.

Closes #206
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit d94a322 into dev Sep 29, 2026
17 checks passed

@ZhuchkaTriplesix ZhuchkaTriplesix left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

123

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant