Skip to content

fix: add resource limit in zen-proxy.mjs (CWE-770) - #3

Closed
anupamme wants to merge 1 commit into
12errh:mainfrom
anupamme:fix-repo-zen-proxy-cwe-770-rate-limiting
Closed

anupamme wants to merge 1 commit into
12errh:mainfrom
anupamme:fix-repo-zen-proxy-cwe-770-rate-limiting

Conversation

@anupamme

Copy link
Copy Markdown

The proxy server lacks any rate limiting mechanism. While requestStats tracks metrics for display purposes, no enforcement exists to prevent request flooding. The router processes all incoming requests immediately without throttling or quota checks. The affected code is zen-proxy.mjs:1. This change is the fix I would apply.

Reference: CWE-770

What changed

  • zen-proxy.mjs

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@12errh

12errh commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Fair catch — the proxy had no request limiting at all. I didn't take this version because it throttles every route, so the dashboard (which polls /api/status every 4s), /health and the static assets all get 429'd. Self-inflicted outage.

Shipped instead: limiting is scoped to the chat endpoints only, /health and /api/* are never throttled, per-client sliding window, sends Retry-After, and it's off by default (rateLimitMax: 0) so nobody's setup changes silently. Config + env var if you want it on.

@12errh 12errh closed this Sep 25, 2026
@anupamme

Copy link
Copy Markdown
Author

Thanks for addressing this. The main concern was the lack of any enforcement mechanism on the request path, and the new approach addresses that while avoiding throttling of dashboard/health endpoints.

The scoped chat-endpoint limiting, per-client window, Retry-After, and opt-in configuration make sense.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants