In this newly disclosed #curl security report it is painfully obvious how the user's "clever" idea of using an AI to write the report made the report into a impenetrable wall of text instead of simply stating the problem in a few coherent paragraphs.
curl disclosed on HackerOne: libcurl: Host-Only Cookies Leak to...
libcurl canonicalizes numeric IPv4 hostnames during URL parsing and redirect handling (example: 127.000.000.001 to 127.0.0.1). When a host-only cookie (no Domain= attribute) is set, it is stored in...HackerOne
xyhhx 🔻
in reply to daniel:// stenberg:// • • •Stéphane Bortzmeyer
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Stéphane Bortzmeyer • • •John Kristoff
in reply to daniel:// stenberg:// • • •Mike Roach
in reply to daniel:// stenberg:// • • •Poolitzer
in reply to daniel:// stenberg:// • • •it's missing 🎃 --> 39c3
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to it's missing 🎃 --> 39c3 • • •Kaito
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Kaito • • •