add size limit handler to limit req/resp size (#4310) (#4313)
details
- Finding IDs
- F-CONFLUENTIC-SCHEMA-REGISTRY-REST-BODY-NOCAP-001
- Status
- fixed publicly
- Reported via
- private security contact
- Note
- public commit bd56596 on 2026-05-18 adds Jetty SizeLimitHandler, size.limit.handler.enabled and max.request.body.size configuration, plus RestApiRequestBodySizeClusterTest coverage for HTTP 413 on oversized request bodies. releases v8.0.6, v8.1.4, v8.2.2, and v8.3.0 contain the fix; v8.0.6 was tagged 2026-06-19.
F-CONFLUENTIC-SCHEMA-REGISTRY-REST-BODY-NOCAP-001: Resource limits. REST body processing requires a configured request-size limit. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CONFLUENTIC-SCHEMA-REGISTRY-REST-BODY-NOCAP-001
Security area (1seal assessment): Availability. A configurable body-size handler bounds request/response buffering; the inspected patch leaves this control disabled by default. Reviewed 21 Sep 2026.