Skip to content

fix: request target host confusion#512

Open
stevencartavia wants to merge 1 commit into
wevm:mainfrom
stevencartavia:fix-request-target-host-confusion
Open

fix: request target host confusion#512
stevencartavia wants to merge 1 commit into
wevm:mainfrom
stevencartavia:fix-request-target-host-confusion

Conversation

@stevencartavia
Copy link
Copy Markdown

Fixed the Node adapter so a request target's authority can no longer override the host from the Host header. Protocol-relative (//evil.com/x) and similar targets previously hijacked the host and poisoned the auto-detected realm.

Added conformance tests, including a raw-socket harness.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant