Wikipedia language subdomain was derived from user input without validation, allowing attackers to redirect requests via malicious language values like "evil.com.attacker.com". Added a whitelist of valid Wikipedia language codes to prevent this. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| autocomplete | ||
| cache | ||
| config | ||
| contracts | ||
| engines | ||
| httpapi | ||
| middleware | ||
| search | ||
| upstream | ||
| views | ||