arturobernalg opened a new pull request, #705:
URL: https://github.com/apache/httpcomponents-core/pull/705

   `SETTINGS_HEADER_TABLE_SIZE` defines the maximum table size permitted by the 
peer. It does not require the encoder to use the entire advertised capacity.
   
   At present the remote value is passed directly to the HPACK encoder. A peer 
can therefore advertise a very large value and allow the outbound dynamic table 
to grow well beyond its initial size, increasing memory usage and lookup cost.
   
   Keep the encoder table bounded by the local initial table size while still 
honoring smaller values advertised by the peer.
   
   A similar limit is applied by other HTTP/2 implementations to keep HPACK 
encoder resource usage bounded.
   
   A similar issue was addressed in Netty (GHSA-8352-h356-c9qh) by imposing a 
local upper bound on the HPACK encoder table size.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to