Skip to content

v5.2.2

Compare
Choose a tag to compare
@VojtechVitek VojtechVitek released this 20 Jun 13:31
· 13 commits to master since this release
23c395f

What's Changed

Security fix

  • Fixes GHSA-vrw8-fxc6-2r93 - "Host Header Injection Leads to Open Redirect in RedirectSlashes" commit
    • a lower-severity Open Redirect that can't be exploited in browser or email client, as it requires manipulation of a Host header
    • reported by Anuraag Baishya, @anuraagbaishya. Thank you!

New Contributors

Full Changelog: v5.2.1...v5.2.2