Skip to content
GSSA-2026-05-J0ZPKKGITLAB-GSSA-2026-05-J0ZPKKMay 6, 2026
8.7 High

Unbounded request body on webhook and CI endpoints

The GitHub webhook and CI check-pr API routes read the full request body before any validation. Anyone able to reach the endpoints could post a multi-GB body and exhaust process memory. Fixed by adding a streaming size cap (1MB and 2MB respectively) that returns 413 before signature or JWT verification.

Affected (1)

  • gelhaus-solutionscontributer-checker
    • ≥ 0.0.0Fixed in 0.0.1

Mitigations

Workarounds

  • Place a reverse proxy (nginx/Caddy/Traefik) in front of the deployment with `client_max_body_size 1m` (and a separate 2 MB rule for /api/ci/check-pr).
  • Restrict ingress to /api/github/webhook to GitHubs published webhook IP ranges and to /api/ci/check-pr to your runner egress IPs.

Solutions

  • Upgrade to 0.0.1: a new readLimitedBody helper streams the request body, aborts past the cap, and the routes return 413 before signature/JWT verification. Caps: 1 MB for /api/github/webhook, 2 MB for /api/ci/check-pr.

Exploits

  • 1. Open N concurrent HTTP/1.1 connections to https://victim/api/github/webhook (or /api/ci/check-pr). 2. Each request sends a multi-GB body. 3. The Node process buffers each body in memory before signature/JWT verification can run. 4. Host exhausts RAM and crashes.

Configurations

  • All deployments without a reverse-proxy body-size limit in front of the Node app.
  • Particularly impactful on memory-constrained hosts (small VMs, containers with low RAM limits).

Overview

Webhook and CI endpoints accepted arbitrarily large bodies, enabling memory-exhaustion DoS.

Severity

CVSS v4
8.7 High
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
Low
Attack requirements
None
Privileges required
None
User interaction
None
Confidentiality (vulnerable system)
None
Integrity (vulnerable system)
None
Availability (vulnerable system)
High
Confidentiality (subsequent system)
None
Integrity (subsequent system)
None
Availability (subsequent system)
None
CVSS v3
7.5 High
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Weaknesses (2)

References (4)

Credits (2)

  • Enno Gelhaus
    Remediation developer · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Finder · egelhaus@ennogelhaus.de

Context

Impacts

  • Unauthenticated remote denial of service via memory exhaustion of the Node process.

    CAPEC-130

© 2026 Gelhaus Solutions