top | item 46167794

(no title)

jadamson | 2 months ago

> The body parsing logic is in react or nextjs, that's my takeaway, is it that incorrect?

The exploit they were trying to protect against is in React services run by their customers.

discuss

order

notepad0x90|2 months ago

that makes better sense now, thanks. I feel dumb now that I re-read it, in my mind they patched nextjs/react and the new patch somehow required more buffer size.