In monetr, unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
The public Stripe webhook endpoint fully reads the request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST bodies and cause substantial memory growth, leading to denial of service.