## Bug
**File:** `internal/handlers/webhook.go`, `HandleWebhook()`, line ~30
**Severity:** MEDIUM — Denial of Service
### Description
The webhook handler reads the entire request body without any size limit:
```go
body, readErr := io.ReadAll(request.Body)
```
An attacker who knows (or guesses) a webhook URL can send an arbitrarily large payload, consuming all available memory and causing the process to OOM.
The webhook endpoint is unauthenticated (protected only by the secret in the URL), making this externally exploitable.
### Suggested Fix
Use `io.LimitReader` to cap the body size:
```go
const maxWebhookBodySize = 1 << 20 // 1MB
body, readErr := io.ReadAll(io.LimitReader(request.Body, maxWebhookBodySize))
```
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bug
File:
internal/handlers/webhook.go,HandleWebhook(), line ~30Severity: MEDIUM — Denial of Service
Description
The webhook handler reads the entire request body without any size limit:
An attacker who knows (or guesses) a webhook URL can send an arbitrarily large payload, consuming all available memory and causing the process to OOM.
The webhook endpoint is unauthenticated (protected only by the secret in the URL), making this externally exploitable.
Suggested Fix
Use
io.LimitReaderto cap the body size:this is already fixed in #6