python-hyper / h2

Pure-Python HTTP/2 protocol implementation
https://python-hyper.org/
MIT License
968 stars 157 forks source link

Potential issue for request smuggling #1285

Open tepel-chen opened 1 week ago

tepel-chen commented 1 week ago

I would like to report a potential bug I found, which I previously submitted via email on November 1st. Since I haven’t received a response, I wanted to follow up here in case the email was missed or if GitHub is a more appropriate place for this report.

As I am not a security expert, I cannot fully assess the potential impact of this bug. Should I share further details here, or would it be better to contact someone privately? Thank you for your time and attention to this matter.

Kriechi commented 1 week ago

Please follow the Security Vulnerability Disclosure process documented here: https://python-hyper.org/en/latest/security.html#vulnerability-disclosure

In case you already reported your finding to the mentioned email address, feel free to directly address it to me (you can find my email address via the git commit history) or jump into our team chat at https://app.gitter.im/#/room/#python-hyper_community:gitter.im to ask for more contact options.