- From: Anne van Kesteren <notifications@github.com>
- Date: Sat, 03 Jan 2026 13:36:13 -0800
- To: whatwg/url <url@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Saturday, 3 January 2026 21:36:17 UTC
annevk left a comment (whatwg/url#893) If the filter rejects it, why does it get to go to the parser? That doesn't seem like a sound security setup. Also, the premise of this entire issue seems to be https://blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf from 2017 which is essentially re-documenting an issue known well before that. Which is that you want to use the same URL parser everywhere, which is the goal of this standard. -- Reply to this email directly or view it on GitHub: https://github.com/whatwg/url/issues/893#issuecomment-3707373882 You are receiving this because you are subscribed to this thread. Message ID: <whatwg/url/issues/893/3707373882@github.com>
Received on Saturday, 3 January 2026 21:36:17 UTC