[confighttp] Enforce max_request_body_size before snappy decompression
details
- Finding IDs
- F-OTELCOLLECTOR-001
- Status
- fixed publicly in v0.152.0
- Reported via
- GitHub Security Advisory GHSA-xp52-4g49-prf2
- Note
- accepted private advisory opened 2026-02-23 with reporter credit to @1seal; public issue #15252 and PR #15253 fixed the confighttp snappy decode allocation-before-cap bug. release v1.58.0/v0.152.0, published 2026-05-11, includes the bugfix: Enforce max_request_body_size on Content-Encoding: snappy requests before the decoded buffer is allocated. collector-releases v0.152.0 binaries followed on 2026-05-12. fixed from v0.152.0; v0.151.x and below in the affected range should not be treated as fixed.
F-OTELCOLLECTOR-001: Resource limits. Snappy decoded allocation occurs before the request-body size cap. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-OTELCOLLECTOR-001
Security area (1seal assessment): Availability. The decoded Snappy size is checked before allocating the full output buffer, enforcing the configured request-body limit. Reviewed 21 Sep 2026.