Skip to content

Add Content-Length and request timeout for webhook dispatch #493

Description

@DeFiVC

What

The webhook dispatcher sends HTTP requests without enforcing a maximum response size, potentially allowing a malicious webhook endpoint to send an unbounded response that consumes server memory.

Why

When the dispatcher calls webhook.sendWebhook(), it reads the full response body with response.text(). A malicious endpoint could return a multi-GB response, causing the server to run out of memory.

Scope

  • Limit response body reading to a reasonable size (e.g., 1MB)
  • Use AbortController with size-based limits
  • Log and reject webhooks with oversized responses

Acceptance Criteria

  • Response body is limited to a configurable max size
  • Oversized responses are logged and treated as failures
  • No memory exhaustion from malicious webhook endpoints

Technical Context

  • File: src/services/webhook-dispatcher.ts:70
  • Current: const responseBody = await response.text();
  • Proposed: Read with a size limit using response.arrayBuffer() + check length

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programbugSomething isn't workinghigh

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions