Repository navigation
OOM a potential denial of service in the CGI server on Windows #119452
Description
Activity
- addedtype-securityA security issueA security issuestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes
on May 23, 2024 Correct me if I'm wrong, but the incriminated lines are the following right:
Lines 1226 to 1227 in c85e352
if self.command.lower() == "post" and nbytes > 0: data = self.rfile.read(nbytes) If so, could I perhaps take on this one? (I never directly contributed to CPython so I think I can take this one to setup everything that's needed, unless you are already working on it).
- added a commit that references this issue
on May 23, 2024 Thank you for volunteering @picnixz, but I already have a solution. I have been somewhat delayed in publishing it because I discovered other problem: the large body was truncated on Windows, because
SocketIO.read()is unbuffered and can return a partial data.No worries! I think you are much faster than me on that since I'm not really familiar with the http and IO-related codebase.
Given this code has been removed for 3.15 (gh-133810), do we need to fix this on older versions or can we close this issue?
29 remaining items
- added 4 commits that reference this issue
on Dec 5, 2025 - added a commit that references this issue
on Dec 5, 2025 - added a commit that references this issue
on Dec 15, 2025 All the backports are merged now.
- moved this from Todo to Done in Release and Deferred blockers 🚫
on Jan 26, 2026 The test is a little bit fragile. Example of failure on "AMD64 FreeBSD Refleaks 3.13" buildbot: https://buildbot.python.org/#/builders/1615/builds/1722
ERROR: test_large_content_length_truncated (test.test_httpservers.CGIHTTPServerTestCase.test_large_content_length_truncated) ---------------------------------------------------------------------- Traceback (most recent call last): File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/test/test_httpservers.py", line 1028, in test_large_content_length_truncated res = self.request('/cgi-bin/file1.py', 'POST', b'x', headers) File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/test/test_httpservers.py", line 89, in request return self.connection.getresponse() ~~~~~~~~~~~~~~~~~~~~~~~~~~~^^ File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/http/client.py", line 1450, in getresponse response.begin() ~~~~~~~~~~~~~~^^ File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/http/client.py", line 336, in begin version, status, reason = self._read_status() ~~~~~~~~~~~~~~~~~^^ File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/http/client.py", line 297, in _read_status line = str(self.fp.readline(_MAXLINE + 1), "iso-8859-1") ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^ File "/buildbot/buildarea/3.13.ware-freebsd.refleak/build/Lib/socket.py", line 723, in readinto return self._sock.recv_into(b) ~~~~~~~~~~~~~~~~~~~~^^^ ConnectionResetError: [Errno 54] Connection reset by peerOne explanation is the hardcoded timeout of 1 ms in the test:
with support.swap_attr(self.request_handler, 'timeout', 0.001):
This timeout is too low if the machine running the test has high system load.
For example,
./python -m test test_httpservers -v -m test_large_content_length_truncated -F -j10fails quickly.
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
When
http.server.CGIHTTPRequestHandleron Windows (and other platforms withoutfork()) handles the POST request, it reads the whole body of the POST request in memory before sending it to the subprocess running the script. The underlying SocketIO allocates the amount of memory specified in theContent-Lengthheader before actual reading the data, so a small request with incorrectContent-Lengthcan cause consumption of the large amount of memory and CPU time and can be used in the DOS attack on the server.Linked PRs