You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Slow performance has been affecting parsing headers in requests with Content-Type: application/x-www-form-urlencoded header, when trying to parse the form submitted.
Having minimal application which parses form from request like this:
would cause excessive load and making workers timeout.
The request should've been parsed without overloading the worker and extracted the form arguments as usual.
I'm planning to make a PR which should fix this issue.
Environment:
Python version: latest
Werkzeug version: latest
The text was updated successfully, but these errors were encountered:
davidism
changed the title
ReDoS while parsing headers in Content-Type: application/x-www-form-urlencoded requests
Slow performance parsing certain Content-Type: application/x-www-form-urlencoded headers
May 17, 2024
Slow performance has been affecting parsing headers in requests with
Content-Type: application/x-www-form-urlencoded
header, when trying to parse the form submitted.Having minimal application which parses form from request like this:
making a request with specially crafted headers like this:
would cause excessive load and making workers timeout.
The request should've been parsed without overloading the worker and extracted the form arguments as usual.
I'm planning to make a PR which should fix this issue.
Environment:
The text was updated successfully, but these errors were encountered: