#498 Memory: Days filter unbounded query DoS

closed medium Created 2025-12-17 02:57 · Updated 2025-12-17 15:56

Description

Edit
api/blueprints/v1/workflows.py:814-885 - No upper bound on days param. User can request days=36500 loading millions of rows. FIX: MAX_DAYS_FILTER=90 and add LIMIT.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...