Skip to content

config: clarify sensitive redirect headers match net/http - #924

Merged
roidelapluie merged 1 commit into
prometheus:mainfrom
roidelapluie:roidelapluie/redirect-header-comment
Jul 10, 2026
Merged

roidelapluie merged 1 commit into
prometheus:mainfrom
roidelapluie:roidelapluie/redirect-header-comment

Conversation

@roidelapluie

Copy link
Copy Markdown
Member

The stripped header list (including Proxy-Authorization and Proxy-Authenticate) now matches makeHeadersCopier in net/http, which gained the Proxy-* entries in the fix for CVE-2025-4673.

The stripped header list (including Proxy-Authorization and
Proxy-Authenticate) now matches makeHeadersCopier in net/http, which
gained the Proxy-* entries in the fix for CVE-2025-4673.

Signed-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com>

@krajorama krajorama left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

stamp

@roidelapluie
roidelapluie merged commit f915876 into prometheus:main Jul 10, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants