1sealsemantic last-mile verification

Research / Finding

bound the verify endpoint request body

F-HEADSCALE-001-002

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
juanfont/headscaleReported fixjuanfont/headscale

bound the verify endpoint request body

Fixed in: v0.29.0

fixed publicly
details
Finding IDs
F-HEADSCALE-001-002
Status
fixed publicly
Fixed in
v0.29.0
Disclosure date
Note
The /verify handler previously read the request body without a local size cap. Commit 42b8c779 of 10 April 2026 wraps it in http.MaxBytesReader with a 4 KiB limit before io.ReadAll, returns HTTP 413 for oversized input and adds tests. The bounded reader is present in stable v0.29.0, replacing the earlier source-only release caveat. This is distinct from the /machine/map body-limit finding. Matching is by the reported callsite and patch; release availability does not establish vendor credit or deployment to every Headscale server.

F-HEADSCALE-001-002: Resource limits. Verification request bodies are not bounded before processing. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-HEADSCALE-001-002

Security area (1seal assessment): Availability. The request body is capped before an unbounded allocation in the verification handler. Reviewed 26 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.