Skip to content

OOM a potential denial of service in the CGI server on Windows #119452

Description

@serhiy-storchaka

When http.server.CGIHTTPRequestHandler on Windows (and other platforms without fork()) handles the POST request, it reads the whole body of the POST request in memory before sending it to the subprocess running the script. The underlying SocketIO allocates the amount of memory specified in the Content-Length header before actual reading the data, so a small request with incorrect Content-Length can cause consumption of the large amount of memory and CPU time and can be used in the DOS attack on the server.

Linked PRs

Activity

  1. added
    stdlibStandard Library Python modules in the Lib/ directory
    3.11only security fixes
    3.12only security fixes
    3.13only security fixes
    3.14bugs and security fixes
    on May 23, 2024
  2. picnixz commented on May 23, 2024

    @picnixz
    Member

    Correct me if I'm wrong, but the incriminated lines are the following right:

    cpython/Lib/http/server.py

    Lines 1226 to 1227 in c85e352

    if self.command.lower() == "post" and nbytes > 0:
    data = self.rfile.read(nbytes)

    If so, could I perhaps take on this one? (I never directly contributed to CPython so I think I can take this one to setup everything that's needed, unless you are already working on it).

  3. added a commit that references this issue on May 23, 2024
  4. serhiy-storchaka commented on May 23, 2024

    @serhiy-storchaka
    MemberAuthor

    Thank you for volunteering @picnixz, but I already have a solution. I have been somewhat delayed in publishing it because I discovered other problem: the large body was truncated on Windows, because SocketIO.read() is unbuffered and can return a partial data.

  5. picnixz commented on May 23, 2024

    @picnixz
    Member

    No worries! I think you are much faster than me on that since I'm not really familiar with the http and IO-related codebase.

  6. cmaloney commented on Oct 26, 2025

    @cmaloney
    Contributor

    Given this code has been removed for 3.15 (gh-133810), do we need to fix this on older versions or can we close this issue?

  7. 29 remaining items

  8. added 4 commits that reference this issue on Dec 5, 2025
  9. removed
    3.14bugs and security fixes
    on Dec 5, 2025
  10. added a commit that references this issue on Dec 5, 2025
  11. added a commit that references this issue on Dec 15, 2025
  12. added 2 commits that reference this issue on Jan 25, 2026
  13. encukou commented on Jan 26, 2026

    @encukou
    Member

    All the backports are merged now.

  14. vstinner commented on May 13, 2026

    @vstinner
    Member

    The test is a little bit fragile. Example of failure on "AMD64 FreeBSD Refleaks 3.13" buildbot: https://buildbot.python.org/#/builders/1615/builds/1722

    ERROR: test_large_content_length_truncated (test.test_httpservers.CGIHTTPServerTestCase.test_large_content_length_truncated)
    ----------------------------------------------------------------------
    Traceback (most recent call last):
      File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/test/test_httpservers.py", line 1028, in test_large_content_length_truncated
        res = self.request('/cgi-bin/file1.py', 'POST', b'x', headers)
      File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/test/test_httpservers.py", line 89, in request
        return self.connection.getresponse()
               ~~~~~~~~~~~~~~~~~~~~~~~~~~~^^
      File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/http/client.py", line 1450, in getresponse
        response.begin()
        ~~~~~~~~~~~~~~^^
      File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/http/client.py", line 336, in begin
        version, status, reason = self._read_status()
                                  ~~~~~~~~~~~~~~~~~^^
      File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/http/client.py", line 297, in _read_status
        line = str(self.fp.readline(_MAXLINE + 1), "iso-8859-1")
                   ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^
      File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/socket.py", line 723, in readinto
        return self._sock.recv_into(b)
               ~~~~~~~~~~~~~~~~~~~~^^^
    ConnectionResetError: [Errno 54] Connection reset by peer
    

    One explanation is the hardcoded timeout of 1 ms in the test:

    with support.swap_attr(self.request_handler, 'timeout', 0.001):

    This timeout is too low if the machine running the test has high system load.

    For example, ./python -m test test_httpservers -v -m test_large_content_length_truncated -F -j10 fails quickly.

  15. added 2 commits that reference this issue on Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.10 (EOL)end of life3.11only security fixes3.12only security fixes3.13only security fixesrelease-blockerstdlibStandard Library Python modules in the Lib/ directorytopic-IOtype-securityA security issue

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions