Discussion about this post

User's avatar
glendc's avatar

Checked if https://ramaproxy.org/ is vulnarable to it, but no, seems we are fine :) On all parts of it. Thank you for the published research btw!

Jonas's avatar

I partially agree with OP's arguments in comments with @Yan Avlasov about OP's opinions on other approaches to responsible disclosure in regards to publically available exploits in the age of AI-assisted vulnerability discovery. However, I find it counter to their own point that they disclosed this to nginx in April, Apache on May 27th and the other three vendors mentioned (Microsoft, Cloudflare and Envoy) seemingly got no advance notice at all, per the blog post. This seems like favouritism towards nginx at a glance, although I'm sure it has a more complex background that I'd love to hear from OP. Disclosure discussion aside, great find and good blog post.

9 more comments...

No posts

Ready for more?