Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

http: do not allow OBS fold in headers by default #10

Open
wants to merge 1 commit into
base: v14.x-fix-cve-2024-22019
Choose a base branch
from

Commits on Apr 11, 2024

  1. http: do not allow OBS fold in headers by default

    Port nodejs/llhttp#350 to llhttp 2.1.x and
    combine with the rest of 5d4d584 for Node.js 14.x.
    
    Original commit message:
        PR-URL: nodejs-private/node-private#558
        Refs: nodejs-private/node-private#556
        Reviewed-By: Matteo Collina <[email protected]>
        Reviewed-By: Rafael Gonzaga <[email protected]>
        CVE-ID: CVE-2024-27982
    richardlau committed Apr 11, 2024
    Configuration menu
    Copy the full SHA
    913768a View commit details
    Browse the repository at this point in the history