Priyanka Gajbhiye
01/08/2025, 12:28 PMColin
01/10/2025, 4:24 PMZing
01/12/2025, 2:57 PMScar Legion
01/14/2025, 5:48 AMSlackbot
01/15/2025, 3:56 PMsquat
01/20/2025, 2:58 PMVishwaraja Pathi
01/21/2025, 8:50 AMShyam Sankar K R
01/26/2025, 4:00 AMMuhammad Asghar Qureshi
01/28/2025, 11:16 AMMalcolm Matalka (Terrateam)
01/31/2025, 8:45 AM-target
. Thought I'd share, Terraliths generally, at the very least, arouse opinionated discussion.
https://github.com/terrateamio/terralithGeorge Fahmy
02/08/2025, 1:54 PMsheldonh
02/11/2025, 7:04 PMJason
02/14/2025, 5:20 PMbradym
02/14/2025, 5:41 PMSrinidhi Sivakumar
02/15/2025, 8:51 AMPePe Amengual
02/20/2025, 7:05 PMOlivier
03/03/2025, 11:48 AMTom Phan
03/05/2025, 1:19 AMDiego Rabatone Oliveira
03/11/2025, 5:42 PMDanila
03/17/2025, 12:46 PMSajja Sudhakara Rao
03/18/2025, 10:59 PMRyan Johnson
03/19/2025, 4:54 PMNoel Jackson
03/20/2025, 2:47 PMJonathan Rose
03/24/2025, 7:50 PMError
golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
Stacktrace
golang-jwt is a Go implementation of JSON Web Tokens. Prior to
5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
Jonathan Rose
03/24/2025, 8:05 PMIgor Rodionov
03/26/2025, 7:46 PMDarya
04/11/2025, 5:30 PMIgnacio Ovsannikov
04/14/2025, 8:42 AMGitmoxi
04/29/2025, 2:57 AMErik Osterman (Cloud Posse)
05/07/2025, 4:26 PM