Details
-
Sub-task
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
1.14
-
None
-
None
Description
protocol-http limits the size of the HTTP response body. However
- There is no limit over the size of the HTTP headers it reads. A bogus server could send an infinite stream of different HTTP headers and cause the fetcher to go out of memory, or send the same HTTP header repeatedly and cause the fetcher to timeout.
- The same goes for the HTTP status line: no check is made concerning its size.
This can be both a performance and a security problem.
Joined is an example python implementation of a server that makes protocol-http receive huge amounts of data and use a lot of CPU (because of NUTCH-2563), without being stopped by http.getTimeout() nor http.getMaxContent().