• Daniel Stenberg's avatar
    - I introduced a maximum limit for received HTTP headers. It is controlled by · 8646cecb
    Daniel Stenberg authored
      the define CURL_MAX_HTTP_HEADER which is even exposed in the public header
      file to allow for users to fairly easy rebuild libcurl with a modified
      limit. The rationale for a fixed limit is that libcurl is realloc()ing a
      buffer to be able to put a full header into it, so that it can call the
      header callback with the entire header, but that also risk getting it into
      trouble if a server by mistake or willingly sends a header that is more or
      less without an end. The limit is set to 100K.
    8646cecb