limit webhook interceptor request bodies before reading them
fixed in public source; rollout not reverified
details
Finding IDs
F-ARGOPROJ-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
the interceptor reads at most 2 MiB plus one byte, rejects an oversized body and adds a regression test. This matches the reported unbounded-read callsite. No unpublished advisory identifier is exposed here; a fixed release was not independently checked.
F-ARGOPROJ-001: Resource limits. Request body consumption lacks an effective size limit. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Availability. A webhook request body must be bounded before allocating memory for the entire input. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.