opencodex: memory exhaustion in the SSE decoder
opencodex SSE decoder - unbounded buffer growth lets a hostile upstream provider exhaust the proxy's memory (GHSA-6f7q-px7c-fqh3)
Fixed in opencodex 2.9.0 (2026-08-01): every streaming translation buffer now has a hard size budget. Track the fix at lidge-jun/opencodex@a616078.
- Product
- opencodex (npm @bitkyc08/opencodex) in lidge-jun/opencodex
- Affected versions
- @bitkyc08/opencodex before 2.9.0. Fixed in 2.9.0 (2026-08-01).
- Severity
- LOW
- Status
- Patched
- Weaknesses
- CWE-400Uncontrolled Resource Consumption
- CWE-770Allocation of Resources Without Limits or Throttling
- GitHub advisory
- GHSA-6f7q-px7c-fqh3
Private; closed by the maintainer after the fix, not published - CVE
- Pending (requested from MITRE)
- Published
- Credit
- Finder: Aaron Elijah Mars of Aeon. Tool: Aeon (https://www.aeon.fun).
What users should do now
- Upgrade opencodex to 2.9.0 or later.
- Point it only at upstream providers you trust.
Summary
opencodex is a long-running local proxy that lets Codex and Claude Code sessions use other LLM providers. Before 2.9.0, its server-sent events decoder kept appending an upstream response to an in-memory buffer until it saw a line break or blank line, with no size limit. A hostile, compromised or broken provider could stream a response with no line breaks and grow the proxy's memory until the process was killed, taking down every local agent session that depends on it. The impact is availability only.
Affected versions
@bitkyc08/opencodex before 2.9.0, when configured to use an upstream provider that the attacker controls or can tamper with.
Impact
- The proxy process runs out of memory and dies, ending all in-flight and later agent sessions until it restarts. Under the service installer, a provider that keeps doing it causes a restart loop.
- No data disclosure or code execution.
Affected code
src/lib/sse-decoder.ts:decodeServerSentEvents()grewbufferanddataLineswithout a bound- Reached from
src/adapters/openai-responses.ts,src/adapters/anthropic.tsandsrc/chat/outbound.ts, which pass the provider's response body straight in
Fix
- a616078 ("bound every translation buffer with a mandatory turn budget") caps both accumulators in the decoder at
TRANSLATOR_MAX_SSE_EVENT_BYTESand covers all three callers. Released in 2.9.0.
Detection (for defenders)
Watch for the opencodex process growing in memory during a single streaming response, or being killed by the system out-of-memory handler.
Timeline
- Reported privately via GitHub PVR (GHSA-6f7q-px7c-fqh3), with a suggested fix.
- Maintainer commits the fix (a616078); opencodex 2.9.0 released the same day.
- Maintainer closes the advisory without publishing it.
- Public write-up; CVE requested from MITRE.
Credit
Finder: Aaron Elijah Mars of Aeon. Tool: Aeon.
References
- Fix commit: lidge-jun/opencodex@a616078
- Fixed release: opencodex 2.9.0
- GitHub advisory: GHSA-6f7q-px7c-fqh3 (private; closed, not published)
- CVE: pending (requested from MITRE)
- Affected repository: lidge-jun/opencodex