GSSA-2026-05-J0ZPKKGITLAB-GSSA-2026-05-J0ZPKKMay 6, 20268.7 High
Unbounded request body on webhook and CI endpoints
The GitHub webhook and CI check-pr API routes read the full request body before any validation. Anyone able to reach the endpoints could post a multi-GB body and exhaust process memory. Fixed by adding a streaming size cap (1MB and 2MB respectively) that returns 413 before signature or JWT verification.
Affected (1)
- gelhaus-solutionscontributer-checker
- ≥ 0.0.0Fixed in 0.0.1
Mitigations
Workarounds
- Place a reverse proxy (nginx/Caddy/Traefik) in front of the deployment with `client_max_body_size 1m` (and a separate 2 MB rule for /api/ci/check-pr).
- Restrict ingress to /api/github/webhook to GitHubs published webhook IP ranges and to /api/ci/check-pr to your runner egress IPs.
Solutions
- Upgrade to 0.0.1: a new readLimitedBody helper streams the request body, aborts past the cap, and the routes return 413 before signature/JWT verification. Caps: 1 MB for /api/github/webhook, 2 MB for /api/ci/check-pr.
Exploits
- 1. Open N concurrent HTTP/1.1 connections to https://victim/api/github/webhook (or /api/ci/check-pr). 2. Each request sends a multi-GB body. 3. The Node process buffers each body in memory before signature/JWT verification can run. 4. Host exhausts RAM and crashes.
Configurations
- All deployments without a reverse-proxy body-size limit in front of the Node app.
- Particularly impactful on memory-constrained hosts (small VMs, containers with low RAM limits).
Overview
Webhook and CI endpoints accepted arbitrarily large bodies, enabling memory-exhaustion DoS.
Severity
CVSS v4
8.7 High
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- None
- User interaction
- None
- Confidentiality (vulnerable system)
- None
- Integrity (vulnerable system)
- None
- Availability (vulnerable system)
- High
- Confidentiality (subsequent system)
- None
- Integrity (subsequent system)
- None
- Availability (subsequent system)
- None
CVSS v3
7.5 High
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- None
- Availability
- High
Weaknesses (2)
References (4)
- CWE-770: Allocation of Resources Without Limits or Throttling (Technical description)
- CWE-400: Uncontrolled Resource Consumption (Technical description)
- OWASP — Denial of Service (Technical description)
- Next.js — Route Segment Config (no default body cap on App Router routes) (Technical description)
Credits (2)
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausFinder · egelhaus@ennogelhaus.de
Context
Impacts
Unauthenticated remote denial of service via memory exhaustion of the Node process.
CAPEC-130