In internal/handlers/webhook.go, HandleWebhook() uses io.ReadAll(request.Body) with no size limit. An attacker who knows (or guesses) a webhook secret can send an arbitrarily large payload to exhaust server memory.
Impact
Denial of service - a single HTTP request with a multi-gigabyte body will consume all available memory.
Use io.LimitReader to cap the request body at a reasonable size (e.g., 1MB).
## Description
In `internal/handlers/webhook.go`, `HandleWebhook()` uses `io.ReadAll(request.Body)` with no size limit. An attacker who knows (or guesses) a webhook secret can send an arbitrarily large payload to exhaust server memory.
## Impact
Denial of service - a single HTTP request with a multi-gigabyte body will consume all available memory.
## Location
`internal/handlers/webhook.go:31` - `body, readErr := io.ReadAll(request.Body)`
## Fix
Use `io.LimitReader` to cap the request body at a reasonable size (e.g., 1MB).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
internal/handlers/webhook.go,HandleWebhook()usesio.ReadAll(request.Body)with no size limit. An attacker who knows (or guesses) a webhook secret can send an arbitrarily large payload to exhaust server memory.Impact
Denial of service - a single HTTP request with a multi-gigabyte body will consume all available memory.
Location
internal/handlers/webhook.go:31-body, readErr := io.ReadAll(request.Body)Fix
Use
io.LimitReaderto cap the request body at a reasonable size (e.g., 1MB).