Ticket #6149 defect closed duplicate
Possible DoS in HTTP chunked decoder
| Reported by: | MostAwesomeDude | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | |
| Component: | web | Keywords: | |
| Cc: | jknight | Branch: | |
| Author: | Launchpad Bug: |
Description
Reported by "ivan" on #twisted.web, along with a PoC.
Only scratched the surface, but I don't see why this isn't a valid problem; the attached PoC does definitely chew 20% of my CPU in return for pegging the target Twisted Web server at 100% on another core.
Attachments
Change History
Note: See
TracTickets for help on using
tickets.

