Skip to content

4.1.8

@Spomky Spomky tagged this 26 Aug 09:47
The compact JWS and JWE serializers split the whole input on every "."
before checking the segment count, so a delimiter-heavy string was first
expanded into one array entry per delimiter. That costs about 25 times
the size of the input in memory: a 2 MB token allocates ~48 MB before it
is rejected as malformed.

The split is now bounded to one more segment than a valid token has,
which is enough to detect and reject longer input while keeping the
allocation proportional to the token itself. The accepted and rejected
inputs are unchanged.

Reported by Team Atlanta.
Assets 2
Loading