in reply to daniel:// stenberg://

the hackerone report behind this is now also public: hackerone.com/reports/2956023