Crowbleed (Crow HTTP framework vulnerability)
Original Post:
We discussed this vulnerability during Episode 154 on 27 September 2022
In responding to a static file request, the Crow HTTP framework would allocate a 16kb buffer and read the target file into it. It would then send the whole buffer to the client regardless of how many bytes were actually read.