Skip to content

Race Condition in Project Creation Allows Bypassing the One-Project Limit #200

Description

@embaby0705

Hello Storj Team,

I found a concurrency issue in the project creation functionality that allows an account limited to one project to create multiple independent projects.

Normally, when an account has a one-project limit and attempts to create an additional project, the application displays:

"Get More Projects"

"Upgrade to Pro Account to create more projects and gain access to higher limits."

However, I found that this restriction can be bypassed by sending multiple legitimate project-creation requests concurrently.

Steps to reproduce:

Use an account limited to one project.
Create a project normally.
Delete the existing project so the account has zero projects.
Start the project creation process again.
Intercept the legitimate project creation request using Burp Suite.
Send the request to Repeater.
Duplicate the request multiple times.
Send the requests concurrently using Burp Suite's parallel/group functionality.
Observe that multiple requests can be accepted and create multiple projects.

I reproduced the issue multiple times:

5 concurrent requests → 2 projects created
12 concurrent requests → 2 projects created
13 concurrent requests → 3 projects created

The resulting projects are separate and persistent resources.

I verified this by deleting one of the created projects and confirming that the other projects remained available and unaffected.

Expected behavior:

An account limited to one project should never be able to have more than one project, even when multiple project creation requests are submitted concurrently.

Actual behavior:

Multiple independent projects can be created concurrently, allowing the account to exceed its configured project limit.

This appears to be a race condition/concurrency issue in the project quota enforcement.

Impact:

A user whose plan allows only one project can bypass the enforced project quota and create multiple independent projects without upgrading to a plan that provides additional project slots.

I originally submitted a detailed security report with video evidence to security-reports@storj.io on Monday, August 17, 2026 at 4:48 AM.

I have not received a response to the security report yet, so I am opening this issue to make sure the report reaches the appropriate team.

Video evidence demonstrating the complete reproduction was already provided with the original security report.

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions