Listen to this Post
The vulnerability exists in two SCA HTTP client modules of ciguard: osv.py and endoflife.py. Both modules call `payload = json.loads(resp.read().decode(‘utf-8’))` without imposing any maximum size limit on the HTTP response body. When ciguard sends a request to hardcoded HTTPS endpoints (endoflife.date or OSV.dev), an attacker who compromises those external services or performs a successful TLS MITM (e.g., via a malicious CA or DNS hijacking that bypasses certificate validation) can return a multi-gigabyte JSON payload. The `resp.read()` call will consume all bytes from the socket, causing the ciguard process to allocate memory proportional to the response size. With a typical CI memory budget of 4–8 GB, a response of 10 GB or more triggers OOM killer termination or excessive swapping. The issue is structural defense-in-depth because HTTPS and certificate validation make MITM unlikely, but unbounded reads remain a risk. The fix adds `MAX_RESPONSE_BYTES = 5 1024 1024` (5 MB) and uses resp.read(MAX_RESPONSE_BYTES + 1). If the read returns more than 5 MB, the function returns `None` and falls back to stale cache. Three regression tests were added. Discovery occurred during ciguard’s self-conducted pentest on 2026-04-26. CVSS v3.1 score 3.7 (Low) with vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L. Reproduction monkey-patches `urllib.request.urlopen` to return a fake 50 MB response; pre-fix memory grows ~50 MB, post-fix memory bounded to 5 MB.
dailycve form:
Platform: ciguard
Version: before patch
Vulnerability: Unbounded memory read
Severity: Low
date: 2026-04-26
Prediction: Patch already issued
What Undercode Say:
Analytics:
Monitor memory usage of ciguard process before fix while true; do ps -o rss,command -C ciguard | tail -1; sleep 1; done Simulate oversized response using mitmproxy mitmproxy --listen-port 8080 --set block_global=false --scripts fake_50mb.py fake_50mb.py returns 50MB JSON payload Test with fixed version using cURL to verify size cap curl --max-filesize 5242880 https://endoflife.date/api/product.json
Exploit:
No working remote exploit without MITM or compromised upstream. For local reproduction: monkey-patch urllib to return large response. Pre-fix code vulnerable:
resp = urllib.request.urlopen(url)
payload = json.loads(resp.read().decode('utf-8')) reads entire response
Attacker controls response → allocate 10GB → OOM kill.
Protection from this CVE:
Apply patch adding `MAX_RESPONSE_BYTES = 5 1024 1024` and bounded read. If patching impossible, run ciguard with memory cgroup limit (e.g., systemd-run --scope -p MemoryMax=2G ciguard) or use a web proxy that enforces response size limits. Upgrade to ciguard version containing commit with `resp.read(MAX_RESPONSE_BYTES + 1)` overflow check.
Impact:
Denial of service via memory exhaustion. Crash of ciguard process in CI pipelines, halting software composition analysis. No data leak or integrity loss. System may become unresponsive if swap exhausted. Limited to memory budgets ≤8 GB; high-memory servers unaffected. Low severity due to HTTPS authentication barrier.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

