Form POST endpoints have no body size limits. Attackers can send very large form bodies.
Suggested fix: Add http.MaxBytesReader wrapper or a body-limit middleware for form endpoints.
## From Security Audit ([#33 comment](https://git.eeqj.de/sneak/webhooker/issues/33#issuecomment-10915))
**Severity: SHOULD-FIX**
Form POST endpoints have no body size limits. Attackers can send very large form bodies.
**Suggested fix:** Add `http.MaxBytesReader` wrapper or a body-limit middleware for form endpoints.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
From Security Audit (#33 comment)
Severity: SHOULD-FIX
Form POST endpoints have no body size limits. Attackers can send very large form bodies.
Suggested fix: Add
http.MaxBytesReaderwrapper or a body-limit middleware for form endpoints.