PT-2021-24421 · Actix Web+1 · Actix-Web+1

Published

2021-12-15

·

Updated

2021-12-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: Perseus versions prior to v0.3.0-beta.21
Description: This issue affects users of the perseus deploy functionality who have not exported their sites to static files and are using the inbuilt Perseus server in production. A memory leak in Actix Web can allow a single user to cause the process to exhaust its memory on low-memory servers by continuously reloading the page. This issue results from certain usage patterns present in Perseus' server mechanics and does not affect all Actix Web applications.
Recommendations: For Perseus versions prior to v0.3.0-beta.21, update to a version after v0.3.0-beta.21 to address the vulnerability. As a temporary workaround, consider switching to the perseus-warp integration, which utilizes Warp, by default. If the instability of the latest beta version of Actix Web is not a concern, the Actix Web integration can be used by adding -i actix-web to perseus serve, but please note that this will print a warning about instability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-GJRJ-9RJ4-PGWX

Affected Products

Actix-Web
Perseus