Skip to content

4.90.0

Compare
Choose a tag to compare
@0xTim 0xTim released this 03 Jan 16:36
· 39 commits to main since this release
6db3d91

⚠️ Security Update ⚠️

This release fixes a long standing issue in Vapor's URI parsing if users attempt to parse untrusted input that could lead to potential host spoofing. This was caused by using a C implementation with a uint16_t index with no bounds checking. For more details see the security advisory GHSA-qvxg-wjxc-r4gg.

This vulnerability has been designated as CVE-2024-21631. Thank you to baarde for reporting!