Skip to content

Latest commit

 

History

History
16 lines (10 loc) · 623 Bytes

File metadata and controls

16 lines (10 loc) · 623 Bytes

lol-html Audit Findings

Security audit of lol-html, Cloudflare's low-output-latency streaming HTML rewriter. Each finding includes a detailed write-up and a patch.

Summary

Total findings: 2 -- Medium: 2

Findings

Streaming parser resource limits

# Finding Severity
001 Unbounded namespace stack growth on nested foreign tags Medium
002 nth-of-type counters bypass the memory limiter Medium