Skip to content

Conversation

bbakerman
Copy link
Member

Its not useful to have 10,000 validation errors in a response

However an attack can use this to DOS the engine and force it to produce lots of validation errors at the expense of CPU nd memory.

This introduces a maximum number of validation errors messages.

@bbakerman bbakerman added this to the 17.3 milestone Sep 18, 2021
@bbakerman bbakerman requested a review from andimarek September 18, 2021 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants