bound the verify endpoint request body
Fixed in: v0.29.0
details
- Finding IDs
- F-HEADSCALE-001-002
- Status
- fixed publicly
- Fixed in
- v0.29.0
- Disclosure date
- Note
- The /verify handler previously read the request body without a local size cap. Commit 42b8c779 of 10 April 2026 wraps it in http.MaxBytesReader with a 4 KiB limit before io.ReadAll, returns HTTP 413 for oversized input and adds tests. The bounded reader is present in stable v0.29.0, replacing the earlier source-only release caveat. This is distinct from the /machine/map body-limit finding. Matching is by the reported callsite and patch; release availability does not establish vendor credit or deployment to every Headscale server.
F-HEADSCALE-001-002: Resource limits. Verification request bodies are not bounded before processing. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-HEADSCALE-001-002
Security area (1seal assessment): Availability. The request body is capped before an unbounded allocation in the verification handler. Reviewed 26 Sep 2026.