summaryrefslogtreecommitdiff
path: root/LICENSE.txt
diff options
context:
space:
mode:
authortoastal2026-04-15 02:08:28 +0000
committerยท๐‘‘๐‘ด๐‘•๐‘‘๐‘ฉ๐‘ค2026-04-15 02:08:28 +0000
commit90b97599704f3f62820841eb1828c519deceadf7 (patch)
treef5e5297343a53f5ad5679309567f95d6cf1390eb /LICENSE.txt
parentfe9270a88cb1c406769b0deb552c5f53fad7e656 (diff)
downloadnixtaml-90b97599704f3f62820841eb1828c519deceadf7.tar
nixtaml-90b97599704f3f62820841eb1828c519deceadf7.tar.gz
nixtaml-90b97599704f3f62820841eb1828c519deceadf7.tar.bz2
nixtaml-90b97599704f3f62820841eb1828c519deceadf7.tar.lz
nixtaml-90b97599704f3f62820841eb1828c519deceadf7.tar.xz
nixtaml-90b97599704f3f62820841eb1828c519deceadf7.tar.zst
nixtaml-90b97599704f3f62820841eb1828c519deceadf7.zip
Fix URI validation bypasses (Phase 1.3 updated)
- Add url_decode function to handle percent-encoded sequences - Check both raw and URL-decoded paths for traversal attacks - Catch %2e%2e%2f (encoded ../) and similar bypasses - Improved path traversal detection for patterns like /etc/../passwd Fixes TPol-identified vulnerabilities: - URL-encoded path traversal bypasses - Missing path traversal detection in some patterns
Diffstat (limited to 'LICENSE.txt')
0 files changed, 0 insertions, 0 deletions