Impact
A roughly 55-byte workflow contract in CUE format could consume unbounded memory and CPU with no time or evaluation budget, taking down a shared control-plane container and every tenant on it. It is reachable by the lowest-privilege role, since any signup owns an organization.
Chainloop accepted workflow contracts in JSON, YAML or CUE. CUE is a Turing-rich configuration language with comprehensions and a standard library; it was compiled with no size, time or evaluation budget, and with no context.Context on the evaluation path.
A constant payload, in which only N varies:
import "list"
a: [for x in list.Range(0,N,1) {x}]
At N = 200k this burns roughly 500 MB and 34 seconds. At N = 1M it does not return, with memory still climbing past 685 MB when cut off. Because no context is threaded through the evaluation path, the server's 10-second request timeout returns an error to the client while the evaluation goroutine keeps running — the work cannot be reclaimed, and it accumulates across requests. A handful of small fire-and-forget requests is enough to exhaust and OOM-kill a shared control-plane container, taking down every tenant on that instance.
Payload size limits do not help against a 55-byte bomb. The properties that matter are boundedness and cancellability, and a general-purpose configuration language does not guarantee either.
Anyone running the Control Plane on a version before 1.103.0 is affected.
Patches
Fixed in v1.103.0, which removes CUE support entirely. Upgrade the Control Plane to v1.103.0 or later.
CUE was a rarely used and never fully supported third contract format behind JSON and YAML. That is why the fix removes it outright rather than bounding the evaluator: no supported workflow depended on it. JSON and YAML contracts are unaffected, so for nearly all users the upgrade requires no change. The stored format value is retained as inert, so contracts already saved as CUE and the existing API remain valid, and no database migration is required.
Chainloop's hosted service (chainloop.dev) is already patched.
Workarounds
None. There is no configuration toggle to refuse CUE contracts before v1.103.0, and payload size limits are not effective against this. Upgrading is required.
References
Impact
A roughly 55-byte workflow contract in CUE format could consume unbounded memory and CPU with no time or evaluation budget, taking down a shared control-plane container and every tenant on it. It is reachable by the lowest-privilege role, since any signup owns an organization.
Chainloop accepted workflow contracts in JSON, YAML or CUE. CUE is a Turing-rich configuration language with comprehensions and a standard library; it was compiled with no size, time or evaluation budget, and with no
context.Contexton the evaluation path.A constant payload, in which only
Nvaries:At
N= 200k this burns roughly 500 MB and 34 seconds. AtN= 1M it does not return, with memory still climbing past 685 MB when cut off. Because no context is threaded through the evaluation path, the server's 10-second request timeout returns an error to the client while the evaluation goroutine keeps running — the work cannot be reclaimed, and it accumulates across requests. A handful of small fire-and-forget requests is enough to exhaust and OOM-kill a shared control-plane container, taking down every tenant on that instance.Payload size limits do not help against a 55-byte bomb. The properties that matter are boundedness and cancellability, and a general-purpose configuration language does not guarantee either.
Anyone running the Control Plane on a version before 1.103.0 is affected.
Patches
Fixed in v1.103.0, which removes CUE support entirely. Upgrade the Control Plane to v1.103.0 or later.
CUE was a rarely used and never fully supported third contract format behind JSON and YAML. That is why the fix removes it outright rather than bounding the evaluator: no supported workflow depended on it. JSON and YAML contracts are unaffected, so for nearly all users the upgrade requires no change. The stored format value is retained as inert, so contracts already saved as CUE and the existing API remain valid, and no database migration is required.
Chainloop's hosted service (chainloop.dev) is already patched.
Workarounds
None. There is no configuration toggle to refuse CUE contracts before v1.103.0, and payload size limits are not effective against this. Upgrading is required.
References