TcpTransport.onData names the peer on both of its WARN tiers:
rejecting malformed frame from ${connection.peer ?? '<unknown peer>'}: ${checked.problem}
wire handler threw on a frame from ${connection.peer ?? '<unknown peer>'}; closing
connection.peer is built from the peer's own hello payload, and isNodeAddressData requires only that systemName and host are non-empty strings — no character class, no length bound. A peer whose host contains a newline renders a log line containing a newline, and ConsoleLogger writes one line per record: the peer forges as many additional records as it likes, each indistinguishable from a genuine one. That is #573's shape, on the socket path.
Under mTLS certificateVouchesFor narrows it, since the claimed address must match the certificate. A plaintext cluster has no such check — the peer need only complete a handshake.
The MessageChannelTransport sibling already sanitises: it escapes LF, CRLF, CR, U+2028 and U+2029 and clips a long host. The same helper applied at the socket seam closes this.
TcpTransport.onDatanames the peer on both of its WARN tiers:connection.peeris built from the peer's ownhellopayload, andisNodeAddressDatarequires only thatsystemNameandhostare non-empty strings — no character class, no length bound. A peer whosehostcontains a newline renders a log line containing a newline, andConsoleLoggerwrites one line per record: the peer forges as many additional records as it likes, each indistinguishable from a genuine one. That is #573's shape, on the socket path.Under mTLS
certificateVouchesFornarrows it, since the claimed address must match the certificate. A plaintext cluster has no such check — the peer need only complete a handshake.The
MessageChannelTransportsibling already sanitises: it escapes LF, CRLF, CR, U+2028 and U+2029 and clips a long host. The same helper applied at the socket seam closes this.