Skip to content

fix: mitigate HTTP Slowloris and log injection in login command (CWE-117,400) - #557

Open
Vaishnav88sk wants to merge 1 commit into
microcks:masterfrom
Vaishnav88sk:fix/security-http-log-issues
Open

Vaishnav88sk wants to merge 1 commit into
microcks:masterfrom
Vaishnav88sk:fix/security-http-log-issues

Conversation

@Vaishnav88sk

Copy link
Copy Markdown
Contributor

Description

This PR resolves two security warnings in the OAuth login command identified by the gosec SAST scanner.

Security Fixes:

  • G112 (CWE-400): The local HTTP server spun up for the OAuth callback did not have a ReadHeaderTimeout configured, making it theoretically vulnerable to a Slowloris DoS attack. A 3-second timeout has been added.
  • G706 (CWE-117): The callback server was directly logging r.URL.Path (user-controlled input), which introduces a log injection risk via newline characters. The path is now sanitized before logging, and a #nosec annotation was added to inform the taint analyzer.

How to test

  1. Run gosec -include=G112,G706 ./cmd/... and verify 0 issues are found.
  2. Run microcks-cli login and ensure the authentication flow still works correctly and the callback path logs as expected.

Signed-off-by: Vaishnav88sk <vaishnavsk8804@gmail.com>

This branch was successfully deployed

1 active deployment
Build — 94da19a2 Deployed Sep 29, 2026 by Vaishnav88sk via build-verify-package #748
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant