Re: [whatwg/url] Malformed URL Normalization in Standard Introduces SSRF Risks (Issue #893)

annevk left a comment (whatwg/url#893)

If the filter rejects it, why does it get to go to the parser? That doesn't seem like a sound security setup. Also, the premise of this entire issue seems to be https://blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf from 2017 which is essentially re-documenting an issue known well before that. Which is that you want to use the same URL parser everywhere, which is the goal of this standard.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/url/issues/893#issuecomment-3707373882
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/url/issues/893/3707373882@github.com>

Received on Saturday, 3 January 2026 21:36:17 UTC