What changed, and why it matters
This patch fixes a size-limit accounting bug in Monero's built-in HTTP server. When a client sends multiple HTTP requests back-to-back on the same connection (pipelining), leftover buffered data from the next request was not being counted toward the server's maximum allowed request size. A malicious or misbehaving client could therefore sneak in a request larger than the configured limit, potentially causing excessive memory use or a denial of service. The fix makes the server count that already-buffered data against the limit when it starts processing the next request.
Treat as a security hardening fix and include in release notes. Users running public RPC nodes or services should upgrade promptly, as exposed HTTP endpoints are the likely attack surface. No immediate emergency response is indicated, but a CVE may be warranted if the project confirms the issue is exploitable for DoS.
Security signals we found
Request size limit bypass via pipelined HTTP caching
Denial-of-service / memory pressure potential from oversized requests
Fix in low-level network protocol handler
Evidence from the diff
In contrib/epee/include/net/http_protocol_handler.inl, the request reset routine previously set m_bytes_read = 0, discarding any bytes already cached for a pipelined follow-on request. The patch initializes m_bytes_read = m_cache.size() instead, so the parser’s content-length / request-size enforcement includes bytes that arrived while the previous request was being handled. This closes a request-size bypass window for HTTP/1.1 pipelined connections.
Changed components
contrib/epee/include/net/http_protocol_handler.inlepee HTTP server / protocol handlerHTTP pipelining request handlingInspect captured patch +2 / −1
### contrib/epee/include/net/http_protocol_handler.inl
@@ -258,7 +258,8 @@ namespace net_utils
m_query_info.clear();
m_len_summary = 0;
m_newlines = 0;
- m_bytes_read = 0;
+ // data already buffered for a pipelined request still counts toward m_max_content_length
+ m_bytes_read = m_cache.size();
return true;
}
//--------------------------------------------------------------------------------------------Why this scored 64/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.