serai-dex / serai

Other
258 stars 47 forks source link

Potential DoS based on unused preprocesses #507

Open kayabaNerve opened 9 months ago

kayabaNerve commented 9 months ago

Parties who submit a late preprocess do not have their preprocess used. Accordingly, their contents go unchecked, enabling them to place the maximum amount of bytes there (as spam) without detection.

This is also possible upon the re-attempt for sessions which were completed and accordingly won't be re-attempted.

kayabaNerve commented 2 weeks ago

Would be resolvable by #588.