Re: [whatwg/url] Malformed URL Normalization in Standard Introduces SSRF Risks (Issue #893)

swhiteman left a comment (whatwg/url#893)

> I very much get the feeling I'm discussing something with an LLM...

The way the convo is talking past Anne despite the same topic being closed in 4 other places has that ring to it.

Even as a longtime WAF skeptic, since before they were called WAFs, I think ‘bypass‘ is an uncanny-valley term, too. Only way there’s a bypass is if the parsed URL is filtered, but the raw URL is forwarded (a TOCTOU-like vulnerability). Is there a vendor that really does this?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/url/issues/893#issuecomment-3708422612
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/url/issues/893/3708422612@github.com>

Received on Sunday, 4 January 2026 21:02:38 UTC