Skip to content

fix: add resource limit in chat.js (CWE-770) - #182

Merged
Rfym21 merged 1 commit into
Rfym21:mainfrom
anupamme:fix-repo-qwen2api-cwe-770-chat-rate-limiting
Sep 27, 2026
Merged

Rfym21 merged 1 commit into
Rfym21:mainfrom
anupamme:fix-repo-qwen2api-cwe-770-chat-rate-limiting

Conversation

@anupamme

Copy link
Copy Markdown
Contributor

The API endpoints in src/routes/chat.js lack rate limiting middleware. Computationally expensive operations like /v1/chat/completions, /v1/images/generations, /v1/images/edits, and /v1/videos are protected only by apiKeyVerify authentication, with no throttling or request rate controls. This allows authenticated attackers to send high-volume requests that can exhaust server resources, API quotas, and backend AI service capacity. The affected code is src/routes/chat.js:35. This change is the fix I would apply.

Reference: CWE-770

What changed

  • src/routes/chat.js
  • package.json

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.

Regression test

The security boundary is maintained under adversarial input

Test
const request = require('supertest');
const express = require('express');
const chatRouter = require('../src/routes/chat');

describe('rate limiting is enforced on expensive AI endpoints', () => {
  const app = express();
  app.use(express.json());
  app.use('/', chatRouter);

  const endpoints = [
    { method: 'post', path: '/v1/chat/completions', payload: { model: 'gpt-4', messages: [{ role: 'user', content: 'test' }] } },
    { method: 'post', path: '/v1/images/generations', payload: { prompt: 'test image' } },
    { method: 'post', path: '/v1/videos', payload: { prompt: 'test video' } }
  ];

  test.each(endpoints)('applies rate limiting to $path', async ({ method, path, payload }) => {
    const authHeader = { 'Authorization': 'Bearer test-key' };
    const requests = Array(15).fill(null).map(() => 
      request(app)[method](path).set(authHeader).send(payload)
    );
    
    const responses = await Promise.all(requests);
    const rateLimited = responses.some(r => r.status === 429);
    
    expect(rateLimited).toBe(true);
  });
});

Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants