Skip to content

fix: add resource limit in gateway.js (CWE-770) - #1

Open
anupamme wants to merge 1 commit into
9pings:masterfrom
anupamme:fix-repo-notjev-gateway-upstream-concurrency-limit
Open

anupamme wants to merge 1 commit into
9pings:masterfrom
anupamme:fix-repo-notjev-gateway-upstream-concurrency-limit

Conversation

@anupamme

Copy link
Copy Markdown

The gateway proxy forwards requests to upstream AI services without per-request rate limiting or cost-based throttling. While timeout (120s) and body size limits (16MB) exist, an attacker with valid API key access can trigger expensive AI model calls without quota enforcement, causing financial drain and resource starvation for legitimate users. The affected code is lib/gateway.js:124. This change is the fix I would apply.

Reference: CWE-770

What changed

  • lib/gateway.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant