Improper resource allocation In github.com/forceu/gokapi
Description
Gokapi vulnerable to DoS in E2E Metadata Parser
Summary
An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users.
Impact
Any authenticated user can crash the Gokapi server by sending concurrent large payloads.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 2.2.4 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.