lucy-xss-filter before commit 7c1de6d allows an attacker...
Moderate severity
Unreviewed
Published
Jan 16, 2026
to the GitHub Advisory Database
•
Updated Jan 16, 2026
Description
Published by the National Vulnerability Database
Jan 16, 2026
Published to the GitHub Advisory Database
Jan 16, 2026
Last updated
Jan 16, 2026
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension.
References