Security

opencodex: memory exhaustion in the SSE decoder

opencodex SSE decoder - unbounded buffer growth lets a hostile upstream provider exhaust the proxy's memory (GHSA-6f7q-px7c-fqh3)

PUBLISHED SEVERITY LOWSTATUS PatchedGHSA-6f7q-px7c-fqh3
Patched

Fixed in opencodex 2.9.0 (2026-08-01): every streaming translation buffer now has a hard size budget. Track the fix at lidge-jun/opencodex@a616078.

Product
opencodex (npm @bitkyc08/opencodex) in lidge-jun/opencodex
Affected versions
@bitkyc08/opencodex before 2.9.0. Fixed in 2.9.0 (2026-08-01).
Severity
LOW
Status
Patched
Weaknesses
  • CWE-400Uncontrolled Resource Consumption
  • CWE-770Allocation of Resources Without Limits or Throttling
As filed on the advisory.
GitHub advisory
GHSA-6f7q-px7c-fqh3
Private; closed by the maintainer after the fix, not published
CVE
Pending (requested from MITRE)
Published
Credit
Finder: Aaron Elijah Mars of Aeon. Tool: Aeon (https://www.aeon.fun).

What users should do now

  1. Upgrade opencodex to 2.9.0 or later.
  2. Point it only at upstream providers you trust.

Summary

opencodex is a long-running local proxy that lets Codex and Claude Code sessions use other LLM providers. Before 2.9.0, its server-sent events decoder kept appending an upstream response to an in-memory buffer until it saw a line break or blank line, with no size limit. A hostile, compromised or broken provider could stream a response with no line breaks and grow the proxy's memory until the process was killed, taking down every local agent session that depends on it. The impact is availability only.

Affected versions

@bitkyc08/opencodex before 2.9.0, when configured to use an upstream provider that the attacker controls or can tamper with.

Impact

  • The proxy process runs out of memory and dies, ending all in-flight and later agent sessions until it restarts. Under the service installer, a provider that keeps doing it causes a restart loop.
  • No data disclosure or code execution.

Affected code

  • src/lib/sse-decoder.ts: decodeServerSentEvents() grew buffer and dataLines without a bound
  • Reached from src/adapters/openai-responses.ts, src/adapters/anthropic.ts and src/chat/outbound.ts, which pass the provider's response body straight in

Fix

  • a616078 ("bound every translation buffer with a mandatory turn budget") caps both accumulators in the decoder at TRANSLATOR_MAX_SSE_EVENT_BYTES and covers all three callers. Released in 2.9.0.

Detection (for defenders)

Watch for the opencodex process growing in memory during a single streaming response, or being killed by the system out-of-memory handler.

Timeline

  1. Reported privately via GitHub PVR (GHSA-6f7q-px7c-fqh3), with a suggested fix.
  2. Maintainer commits the fix (a616078); opencodex 2.9.0 released the same day.
  3. Maintainer closes the advisory without publishing it.
  4. Public write-up; CVE requested from MITRE.

Credit

Finder: Aaron Elijah Mars of Aeon. Tool: Aeon.

References