valyala/fasthttp

It is not safe to read all stream body to memory without a max size limit.

Open

#1,765 opened on 2024年4月23日

GitHub で見る
 (8 comments) (0 reactions) (0 assignees)Go (21,741 stars) (1,755 forks)batch import
help wanted

説明

https://github.com/valyala/fasthttp/blob/57b9352ad1cc93a0aaaa72b2130e03ace8a5b118/http.go#L427 I think it would be safe to stop reading the request body into memory and return an error when it exceeds the maximum request body size. Otherwise, it may lead to an out-of-memory (OOM) error when the request body is too large.

コントリビューターガイド