Skip to content

fix(hackney_url): parses query string before userinfo#753

Merged
benoitc merged 2 commits intobenoitc:masterfrom
tank-bohr:cve-2025-1211
Feb 14, 2025
Merged

fix(hackney_url): parses query string before userinfo#753
benoitc merged 2 commits intobenoitc:masterfrom
tank-bohr:cve-2025-1211

Conversation

@tank-bohr
Copy link
Copy Markdown
Contributor

@tank-bohr tank-bohr commented Feb 12, 2025

@tank-bohr
Copy link
Copy Markdown
Contributor Author

tank-bohr commented Feb 12, 2025

fixes #751

@tank-bohr
Copy link
Copy Markdown
Contributor Author

@benoitc Please take a look. It's the smallest fix I could come up with. It doesn't break the contract thus shouldn't break the existing code. No need to get rid of parsing userinfo. Thank you in advance 🙏

@guipdutrao2e
Copy link
Copy Markdown

this is going to be merged?

@benoitc
Copy link
Copy Markdown
Owner

benoitc commented Feb 13, 2025

@tank-bohr thank you. I'm looking at why tests are failing but it should be good.

@tank-bohr
Copy link
Copy Markdown
Contributor Author

@tank-bohr thank you. I'm looking at why tests are failing but it should be good.

@benoitc I've managed to fix the tests in the #754

@benoitc benoitc merged commit 9594ce5 into benoitc:master Feb 14, 2025
5 checks passed
@benoitc
Copy link
Copy Markdown
Owner

benoitc commented Feb 14, 2025

thank you. I have one another change to merge and will make a release

@halfdan
Copy link
Copy Markdown

halfdan commented Feb 19, 2025

@benoitc Is there an ETA for the release?

@m1234567898
Copy link
Copy Markdown

@benoitc thank you for the quick fix!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Server-side Request Forgery (SSRF) in hackney

5 participants