bundle parsing dos via unbounded tlogentries
details
- Finding IDs
- F-SIG-GO-000-001
- Status
- closed unmerged
- Reported date
- Rationale
- Proposed a cap during bundle parsing; this PR closed without merge on 2026-05-07. A narrower follow-up, #630 by @tonghuaroot, merged on 2026-05-27 and explicitly references #567. It caps decoded tlog entry count before per-entry parsing, but after protojson.Unmarshal; initial JSON decoding allocations remain outside that bound.
- PR opened by
- @1seal
- PR state observed
- closed; GitHub merged: false; 2026-09-24
- PR observation basis
- Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
- Contribution boundary
- @1seal opened this PR; this alone does not establish sole code authorship.
F-SIG-GO-000-001: Resource limits. An unbounded transparency-log entry set consumes excessive resources. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-SIG-GO-000-001
Security area (1seal assessment): Availability. An unbounded transparency-log entry set consumes excessive resources. Reviewed 24 Sep 2026.