Skip to content

Decoding of deflate content-encoding doesn't respect max_body_size #206

@grr

Description

@grr

Responses with deflate content-encoding do not respect the max_body_size option when they are decoded. This leaves them susceptible to decompression bombs. All the other handled compression content-encodings (gzip, br, bzip2) respect the option.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions