Security finding
The verification cache caps entry count but not retained bytes. Identity matching accepts whitespace-padded aliases while the cache and successful-Bind logging retain the raw requested username.
Evidence
identity.Policy.matches trims Unicode whitespace for lowercase_equal.
- Successful identity binding retains the raw requested username.
- The cache key includes that raw username and the token.
cacheMaxEntries is 10,000 entries without a byte budget.
Reproduction
One 565-byte valid JWT was accepted under 512 distinct whitespace-padded aliases and retained 16,654,336 bytes of usernames alone in the positive cache. A real TCP LDAP Bind accepted a 60,017-byte username alias in a 60,661-byte request using a 590-byte JWT.
At roughly 60 KB per retained username, 10,000 entries could retain about 600 MB of usernames alone, above the chart's default 128 MiB memory limit. This is an extrapolation; the review did not intentionally OOM a process.
Impact
An authenticated caller can cause disproportionate cache and logging memory/volume pressure using one valid token. Expired entries are not eagerly deleted and the command's reaper interval is five minutes.
Proposed direction
- Bound accepted usernames before verification.
- Bound cache and retained-claim bytes, not only entry count.
- Canonicalize identity only if that preserves the cache's identity-binding security invariant.
- Bound logged successful usernames.
- Eagerly remove expired entries when observed.
Validation
Add regressions for Unicode-whitespace aliases, cache byte accounting, bounded successful-Bind logs, and cache-key isolation in both directions.
Security finding
The verification cache caps entry count but not retained bytes. Identity matching accepts whitespace-padded aliases while the cache and successful-Bind logging retain the raw requested username.
Evidence
identity.Policy.matchestrims Unicode whitespace forlowercase_equal.cacheMaxEntriesis 10,000 entries without a byte budget.Reproduction
One 565-byte valid JWT was accepted under 512 distinct whitespace-padded aliases and retained 16,654,336 bytes of usernames alone in the positive cache. A real TCP LDAP Bind accepted a 60,017-byte username alias in a 60,661-byte request using a 590-byte JWT.
At roughly 60 KB per retained username, 10,000 entries could retain about 600 MB of usernames alone, above the chart's default 128 MiB memory limit. This is an extrapolation; the review did not intentionally OOM a process.
Impact
An authenticated caller can cause disproportionate cache and logging memory/volume pressure using one valid token. Expired entries are not eagerly deleted and the command's reaper interval is five minutes.
Proposed direction
Validation
Add regressions for Unicode-whitespace aliases, cache byte accounting, bounded successful-Bind logs, and cache-key isolation in both directions.