#401 LOW: API pagination offset unbounded for DoS

closed low Created 2025-12-11 22:44 · Updated 2025-12-11 22:50

Description

Edit
API endpoints (logs.py:1220, schedules.py:685) don't bound offset. Large offset=999999999 forces PostgreSQL to skip massive rows. Fix: Add max_offset validation or keyset pagination.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...