mirror of
https://github.com/rclone/rclone.git
synced 2026-10-10 15:01:37 -04:00
rest.ReadBody read the whole response body into memory with no limit. It is used by the default error handler and by many backends' error handlers and small API calls, so a server which answered with an error status and then streamed an endless body could make rclone allocate memory until it was killed. ReadBody now reads at most 10 MiB (the same limit drainAndClose already uses to discard unread bodies) and returns an error if the body is bigger than that. Every caller reads small API responses - error bodies, status documents and upload tokens - so no legitimate response is affected. Reported by @manus-pi