-
Notifications
You must be signed in to change notification settings - Fork 26
Open
whatwg/fetch
#1434Labels
bugSomething isn't workingSomething isn't working
Description
These new headers increase the size of an HTTP request and coupled with attacker-controlled headers or header values could be used to carry out certain cookie-size sniffing attacks.
Privacy measures in browsers might invalidate some of these attacks, but the privacy boundary is typically not the origin, at least in today's implementations.
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working