Skip to content

Conversation

@nlsj1985
Copy link
Contributor

Bumping llhttp to solve 3 critical CVE's:
MagicStack/httptools/issues/82

Pls note that CRLF delimited headers are required (per HTTP spec also) since the 6.0.7 security update of NodeJS / llhttp

pls note that CRLF delimited headers are required (per HTTP spec also) since the 6.0.7 security update of NodeJS / llhttp
@nlsj1985nlsj1985 mentioned this pull request Sep 1, 2022
Copy link
Member

@elpranselprans left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks!

@elpranselprans merged commit 56d6a16 into MagicStack:masterSep 13, 2022
elprans added a commit that referenced this pull request Sep 13, 2022
Changes ======= * Bump bundled llhttp to 6.0.9 fixes CVE-2022-32213, CVE-2022-32214, CVE-2022-32215 (by @nlsj1985 in 56d6a16 for #83) * Test and build against Python 3.11 (by @elprans in 509cd14 for #84)
@elpranselprans mentioned this pull request Sep 13, 2022
@nlsj1985nlsj1985 deleted the llhttp-v6.0.9 branch September 24, 2022 14:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nlsj1985@elprans