- Notifications
You must be signed in to change notification settings - Fork136
PermalinkChoose a base ref {{ refName }}default Choose a head ref {{ refName }}default Checking mergeability… Don’t worry, you can still create the pull request.
Comparing changes
Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also orlearn more about diff comparisons.
Open a pull request
Create a new pull request by comparing changes across two branches. If you need to, you can also.Learn more about diff comparisons here.
base repository:swift-server/async-http-client
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
Uh oh!
There was an error while loading.Please reload this page.
base:main
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}defaultLoading
...
head repository:swift-server/async-http-client
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
Uh oh!
There was an error while loading.Please reload this page.
compare:http-client-1.12
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}defaultLoading
Uh oh!
There was an error while loading.Please reload this page.
- 1commit
- 4files changed
- 1contributor
Commits on Jan 17, 2023
Merge pull request fromGHSA-v3r5-pjpm-mwgq
MotivationAllowing arbitrary data in outbound header field values allows for thepossibility that users of AHC will accidentally pass untrusted data intothose values. That untrusted data can substantially alter the parsingand content of the HTTP requests, which is extremely dangerous. Theresult of this is vulnerability to CRLF injection.ModificationsAdd validation of outbound header field values.ResultNo longer vulnerable to CRLF injection(cherry picked from commit 3034835a213babfcda19031e80c0b7c9780475e9)
Lukasa authoredJan 17, 2023
Loading
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:git diff main...http-client-1.12
Uh oh!
There was an error while loading.Please reload this page.