Skip to content

Let's nullify CVE-2026-21637 #1568

@aduh95

Description

@aduh95

I was discussing with @mcollina that we probably misjudged CVE-2026-21637, on a second look it doesn't look like a vulnerability, rather than a bug. The user responsibility is to not throw in that event handler, it's user code so outside of our threat model.

If revoking CVEs is a thing, I suggest we do that so users can adjust their expectations.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions