Download
| Alert*
ALAS2-2023-2194 --- cri-tools
http2/hpack: avoid quadratic complexity in hpack decoding The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value
|