Re: [whatwg/fetch] CORS: arbitrary blocking of accept header based on length (#862)

> @RubenVerborgh specific values are somewhat speculative, but informed. Some security bugs around this haven't been opened yet, so I'd rather not discuss in too much detail.

@annevk Following up on this one year later: have (some of) those bugs been made public by now?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/862#issuecomment-578825709

Received on Monday, 27 January 2020 16:18:31 UTC