abersheeran / baize

Powerful and exquisite WSGI/ASGI framework/toolkit.
https://baize.aber.sh
Apache License 2.0
83 stars 3 forks source link

High severity network attack vector in multipart implementation #56

Closed peterschutt closed 1 year ago

peterschutt commented 1 year ago

Hi,

An embargo for a DoS vector affecting the werkzeug multipart implementation expired on the 14th of Feb. I recall from following along with this Starlite issue that your implementation followed the werkzeug pattern, and so I believe your implementation may also be vulnerable.

You can read werkzeug's security advisory here and see their patch here.

abersheeran commented 1 year ago

😯 Thanks!