4 ms·
Any plans to issue a CVE for this HTTP request smuggling attack vector fixed in the latest bun release? https://github.com/oven-sh/bun/issues/29732 https://git
by halifaxbeard 4mo ago
Any plans to issue a CVE for this HTTP request smuggling attack vector fixed in the latest bun release?
https://github.com/oven-sh/bun/issues/29732 https://github.com/oven-sh/bun/issues/29732
- classicposter 4mo agohttps://github.com/oven-sh/bun/security https://github.com/oven-sh/bun/security Surprisingly, they appear to have not disclosed any vulnerabilities whatsoever. It's likely there have been numerous vulnerabilities in the past, but they are all being ignored. https://x.com/DavidSherret/status/2031432509301428644 https://x.com/DavidSherret/status/2031432509301428644
- halifaxbeard 4mo agoThis is really poor form given that Anthropic is going around getting all kinds of public goodwill for finding CVEs in other people’s products.
- shimman 4mo agoYeah! Why would the company that stands to make themselves look better in front of an IPO do such a thing?! Next thing you're going to tell me was that this whole rewrite was another marketing ploy to help potentially turn themselves in multi-millionaires!
- dwattttt 4mo agoYes, it is helpful for a company to be very clear that in a choice between the safety and integrity of their customers, and profit, they are choosing profit.
- grayhatter 4mo agomaybe you should ask on the issue directly?