CursedChrome icon indicating copy to clipboard operation
CursedChrome copied to clipboard

Streaming HTTP responses not handled

Open ZetaTwo opened this issue 4 years ago • 0 comments

The current setup requires the HTTP response to completely finish to be able to return the response to the headers. In some situations, a website will reply with a response of unknown length and use it to stream data as response to other events. This will not work and the request will instead just timeout on the attacker side.

PS. Sorry for dropping a batch of issues like this. We have an ambition of providing PRs as well but letting you know about these things straight away in the meantime.

ZetaTwo avatar Oct 28 '20 14:10 ZetaTwo