Skip to content

v25 LTS security patch#3164

Merged
ahopkins merged 6 commits into
25.12LTSfrom
v25-security
May 31, 2026
Merged

v25 LTS security patch#3164
ahopkins merged 6 commits into
25.12LTSfrom
v25-security

Conversation

@ahopkins

Copy link
Copy Markdown
Member
  • cleanup CRLF header injection
  • resolve chunked trailer request smuggling
  • limit inspector to public methods
  • reject requests where url_bytes exceeds 65535

Copilot AI review requested due to automatic review settings May 31, 2026 18:56
@ahopkins ahopkins requested a review from a team as a code owner May 31, 2026 18:56
@ahopkins ahopkins changed the title cleanup CRLF header injection v25 LTS security patch May 31, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@codecov

codecov Bot commented May 31, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 87.745%. Comparing base (d9738d8) to head (4db4279).

Additional details and impacted files
@@              Coverage Diff               @@
##           25.12LTS     #3164       +/-   ##
==============================================
- Coverage    87.817%   87.745%   -0.073%     
==============================================
  Files           105       105               
  Lines          8143      8152        +9     
  Branches       1290      1291        +1     
==============================================
+ Hits           7151      7153        +2     
- Misses          686       693        +7     
  Partials        306       306               

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@ahopkins ahopkins merged commit a332796 into 25.12LTS May 31, 2026
26 of 28 checks passed
@ahopkins ahopkins deleted the v25-security branch May 31, 2026 19:28
ahopkins added a commit that referenced this pull request May 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants