GHSA-m77f-652q-wwp4
HIGHCVE-2022-3212<bytes::Bytes as axumcore::extract::FromRequest>::fromrequest would not, by default, set a limit for the size of the request body. That meant if a malicious peer would send a very large (or infinite) body your server might run out of memory and crash.
- Affected
- < 0.2.8, = 0.3.0-rc.1
- Fixed in
- 0.2.8
- Weakness
- CWE-770
- Published
- 2022-09-15
- Source
- github