HTParse in Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data or HTTP headers.
HTParse in Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data or HTTP headers.
https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg00002.html https://lynx.invisible-island.net/current/CHANGES.html#index-v2.9.0dev.9 https://bugs.archlinux.org/task/71764?getfile=20606