Bound JSON-RPC input by size and nesting depth

Enforce the nesting bound in one parse, capping allocation by depth, not input size.
This commit is contained in:
xirvik
2026-09-19 02:11:20 +00:00
committed by rakshasa
parent 6c6d2b9333
commit d3f4d18164
5 changed files with 130 additions and 1 deletions
+1
View File
@@ -176,6 +176,7 @@ RpcManager::set_size_limit(uint64_t size) {
throw torrent::input_error("XMLRPC size limit is too small to hold a request.");
m_xmlrpc.set_size_limit(size);
m_jsonrpc.set_size_limit(size);
}
void