Skip to content

fix: mitigate HTTP Slowloris and log injection in login command (CWE-117,400) - #557

Merged
Harsh4902 merged 1 commit into
microcks:masterfrom
Vaishnav88sk:fix/security-http-log-issues
Sep 30, 2026
Merged

Harsh4902 merged 1 commit into
microcks:masterfrom
Vaishnav88sk:fix/security-http-log-issues

Conversation

@Vaishnav88sk

Copy link
Copy Markdown
Contributor

Description

This PR resolves two security warnings in the OAuth login command identified by the gosec SAST scanner.

Security Fixes:

  • G112 (CWE-400): The local HTTP server spun up for the OAuth callback did not have a ReadHeaderTimeout configured, making it theoretically vulnerable to a Slowloris DoS attack. A 3-second timeout has been added.
  • G706 (CWE-117): The callback server was directly logging r.URL.Path (user-controlled input), which introduces a log injection risk via newline characters. The path is now sanitized before logging, and a #nosec annotation was added to inform the taint analyzer.

How to test

  1. Run gosec -include=G112,G706 ./cmd/... and verify 0 issues are found.
  2. Run microcks-cli login and ensure the authentication flow still works correctly and the callback path logs as expected.

Signed-off-by: Vaishnav88sk <vaishnavsk8804@gmail.com>

@Harsh4902 Harsh4902 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Harsh4902
Harsh4902 merged commit 00f96cc into microcks:master Sep 30, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
Build — 94da19a2 Deployed Sep 29, 2026 by Vaishnav88sk via build-verify-package #748
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants