Skip to content

Fix CVE-2026-19873: bound Repeatable counter_name to prevent DoS - #1

Merged
plicease merged 1 commit into
masterfrom
graham/cve-2026-19873
Sep 21, 2026
Merged

plicease merged 1 commit into
masterfrom
graham/cve-2026-19873

Conversation

@plicease

Copy link
Copy Markdown
Member

Element::Repeatable::process read its repeat count straight from the query string via counter_name with only a positive-integer check, then passed it to repeat(), which deep-clones the whole child subtree once per iteration with no upper bound. This was reachable via a plain unauthenticated GET request and cost super-linear CPU due to constraint field lookups, with nested Repeatables multiplying the effect further.

Add a max_counter attribute on Repeatable (default 100) that clamps the client-supplied count instead of trusting it unbounded, with a counter_clamped flag to signal when clamping occurred. The default is inherited from a new form-level repeatable_max_counter attribute, and max_counter => 0 disables clamping for callers who need it. Direct application calls to repeat() are unaffected.

Mirrors the design from FormFu/HTML-FormFu#72.

Element::Repeatable::process read its repeat count straight from the
query string via counter_name with only a positive-integer check, then
passed it to repeat(), which deep-clones the whole child subtree once
per iteration with no upper bound. This was reachable via a plain
unauthenticated GET request and cost super-linear CPU due to
constraint field lookups, with nested Repeatables multiplying the
effect further.

Add a max_counter attribute on Repeatable (default 100) that clamps
the client-supplied count instead of trusting it unbounded, with a
counter_clamped flag to signal when clamping occurred. The default is
inherited from a new form-level repeatable_max_counter attribute, and
max_counter => 0 disables clamping for callers who need it. Direct
application calls to repeat() are unaffected.

Mirrors the design from FormFu/HTML-FormFu#72.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@plicease
plicease force-pushed the graham/cve-2026-19873 branch from 74ae23b to 1c9b498 Compare September 21, 2026 21:16
@plicease
plicease changed the base branch from master to graham/list-someutils September 21, 2026 21:16
Base automatically changed from graham/list-someutils to master September 21, 2026 22:05
@plicease
plicease merged commit 6d23a06 into master Sep 21, 2026
42 checks passed
@plicease
plicease deleted the graham/cve-2026-19873 branch September 21, 2026 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant