Skip to content

v1.15.9

Choose a tag to compare

@pi0 pi0 released this 19 Mar 20:39
· 569 commits to main since this release

compare changes

🩹 Fixes

  • Preserve %25 in pathname (1103df6)
  • static: Prevent path traversal via double-encoded dot segments (%252e%252e) (c56683d)
  • sse: Sanitize carriage returns in event stream data and comments (ba3c3fe)