GHSA-m77f-652q-wwp4

    Dashboard / Vulnerabilities / GHSA-m77f-652q-wwp4

    GHSA-m77f-652q-wwp4

    Published: 15 Sept 2022Last Modified: 8 Nov 2023

    Summary: axum-core has no default limit put on request bodies

    Details: `<bytes::Bytes as axum_core::extract::FromRequest>::from_request` would not, by default, set a limit for the size of the request body. That meant if a malicious peer would send a very large (or infinite) body your server might run out of memory and crash. This also applies to these extractors which used `Bytes::from_request` internally: - `axum::extract::Form` - `axum::extract::Json` - `String` The fix is also in `axum-core` `0.3.0.rc.2` but `0.3.0.rc.1` _is_ vulnerable. Because `axum` depends on `axum-core` it is vulnerable as well. The vulnerable versions of `axum` are `<= 0.5.15` and `0.6.0.rc.1`. `axum` `>= 0.5.16` and `>= 0.6.0.rc.2` does have the fix and are not vulnerable. The patched versions will set a 2 MB limit by default.

    Affected packages

    Package

    Name: axum-core

    Purl: pkg:cargo/axum-core

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.2.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-m77f-652q-wwp4 | CVE-DB