Skip to content

Stream HTTP wrapper truncate redirect location to 1024 bytes

Moderate
bukka published GHSA-52jp-hrpf-2jff Mar 13, 2025

Package

No package listed

Affected versions

< 8.1.32
< 8.2.28
< 8.3.18
< 8.4.5

Patched versions

8.1.32
8.2.28
8.3.19
8.4.5

Description

There is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per https://www.rfc-editor.org/rfc/rfc9110#name-uri-references , the limit is recommended to 8000. The browser limit is usually around 2048 so 1024 is really too low and it might have a real impact in practice.

Impact

The URI truncation might result in omitting some critical information (e.g. from the query) or even redirection to other resources. It could even result in DOS of the remote site if the trucated URL results in error.

Workarounds

There is no real workaround for this

Severity

Moderate

CVE ID

CVE-2025-1861

Weaknesses

No CWEs