Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can't the CORS preflight, by itself, be a DoS?


If you read the OP they say they were specifically crafting links that led to an image resizing webservice, so each load wasn't just requesting static content, it was consuming non-trivial compute cycles. Of course you can have a DDoS comprised of tons of requests for HTML or JPGs but the added overhead of performing a "resize" was at least a part of the plan. Failing a pre-flight would have eliminated that hit.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: