Skip to content

config: clarify sensitive redirect headers match net/http#924

Open
roidelapluie wants to merge 1 commit into
prometheus:mainfrom
roidelapluie:roidelapluie/redirect-header-comment
Open

config: clarify sensitive redirect headers match net/http#924
roidelapluie wants to merge 1 commit into
prometheus:mainfrom
roidelapluie:roidelapluie/redirect-header-comment

Conversation

@roidelapluie

Copy link
Copy Markdown
Member

The stripped header list (including Proxy-Authorization and Proxy-Authenticate) now matches makeHeadersCopier in net/http, which gained the Proxy-* entries in the fix for CVE-2025-4673.

The stripped header list (including Proxy-Authorization and
Proxy-Authenticate) now matches makeHeadersCopier in net/http, which
gained the Proxy-* entries in the fix for CVE-2025-4673.

Signed-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant