Shyam Sankar K R
01/26/2025, 4:00 AMMuhammad Asghar Qureshi
01/28/2025, 11:16 AMMalcolm Matalka (Terrateam)
01/31/2025, 8:45 AM-target
. Thought I'd share, Terraliths generally, at the very least, arouse opinionated discussion.
https://github.com/terrateamio/terralithGeorge Fahmy
02/08/2025, 1:54 PMsheldonh
02/11/2025, 7:04 PMJason
02/14/2025, 5:20 PMbradym
02/14/2025, 5:41 PMSrinidhi Sivakumar
02/15/2025, 8:51 AMPePe Amengual
02/20/2025, 7:05 PMOlivier
03/03/2025, 11:48 AMTom Phan
03/05/2025, 1:19 AMDiego Rabatone Oliveira
03/11/2025, 5:42 PMDanila
03/17/2025, 12:46 PMSajja Sudhakara Rao
03/18/2025, 10:59 PMRyan Johnson
03/19/2025, 4:54 PMNoel Jackson
03/20/2025, 2:47 PMJonathan Rose
03/24/2025, 7:50 PMError
golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
Stacktrace
golang-jwt is a Go implementation of JSON Web Tokens. Prior to
5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
Jonathan Rose
03/24/2025, 8:05 PMIgor Rodionov
03/26/2025, 7:46 PMDarya
04/11/2025, 5:30 PMIgnacio Ovsannikov
04/14/2025, 8:42 AMGitmoxi
04/29/2025, 2:57 AMErik Osterman (Cloud Posse)
05/07/2025, 4:26 PMSlackbot
05/15/2025, 7:27 AMakhan4u
05/20/2025, 5:35 AMErik Osterman (Cloud Posse)
05/21/2025, 8:32 PMAkshay
05/25/2025, 2:57 PMSlackbot
05/28/2025, 9:41 AMAndrew Zeiser
06/05/2025, 5:39 PMRobindeva
06/06/2025, 7:56 AM