So there's this really serious vulnerability. If you're on versions below 0.18.0, the size of the preimage wasn’t checked. An attacker can spam the mint's database with junk data, which is not cool at all.
Not sure why this post keeps bouncing around. First it was in ‘Development & Technical Discussion’ then got moved to Altcoin Discussion... and now back to Project Development? Cashu is tied to Bitcoin, not an altcoin!
Yeah the mint didn’t limit HTLC preimage sizes. Basically, you could just shove massive data blobs with NUT-14 and fill up the disk. v0.18.0 has a fix, but if you’re still on an old version, put some limits on your proxy and application. Agreed, this thread fits better in Bitcoin Development.