Skip to content

Conversation

ManuelBilbao
Copy link
Collaborator

We weren't marking a failure request if the payload conversion to Bytes failed (e.g., because of exceeding the max body length). This could lead to a rate limit bypass for DoS

@ManuelBilbao ManuelBilbao self-assigned this Oct 1, 2025
@ManuelBilbao ManuelBilbao added the signer Signer module label Oct 1, 2025
@jclapis jclapis merged commit a3f8d9d into sigp-audit-fixes Oct 20, 2025
1 check failed
@jclapis jclapis deleted the mark_jwt_failure_widely branch October 20, 2025 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

signer Signer module

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants