Skip to content

[HIGH] Unbounded Retry-After duration DoS vulnerability — code accepts any valid u64  #1287

@ironclaw-ci

Description

@ironclaw-ci

[HIGH:75] Issue Found by Staging CI Review

Severity: HIGH
Confidence: 75/100
PR comment: #1285 (comment)

Description

Unbounded Retry-After duration DoS vulnerability — code accepts any valid u64 from Retry-After header without validation, allowing u64::MAX to freeze application indefinitely in tokio::time::sleep()


Auto-created by staging-ci Claude Code review

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingrisk: mediumBusiness logic, config, or moderate-risk modulesstaging-ci-reviewIssue found during staging CI promotion review

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions