Summary
An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users.
Impact
Any authenticated user can crash the Gokapi server by sending concurrent large payloads.
Summary
An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users.
Impact
Any authenticated user can crash the Gokapi server by sending concurrent large payloads.