Potential security issue by abuse the URL object #1831
Unanswered
lebr0nli
asked this question in
Potential Issue
Replies: 4 comments 3 replies
|
Chatting with @lebr0nli privately. At some point we'll probably need a security correspondence point, but I don't think we're there just yet. |
1 reply
0 replies
|
GitHub has added this to their advisory database, and it is now being picked up by Dependabot dependency scanning. |
0 replies
|
I can't find any open issues, changelog entries, blog entries, or notices stating when this CVE is planned to be fixed. Can someone from the project please provide some official guidance? |
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
I found a potential security issue by abuse the URL parser.
But not sure this is a real vulnerability or just a feature.
Although I think the potential issue I found is not a huge security issue like RCE, I want to talk more privately if possible.
Is there a
security@encode.ioor something I can DM?If there is not, I can share what I found here, too.
All reactions