Skip to content

Let's nullify CVE-2026-21637 #1568

Description

@aduh95

I was discussing with @mcollina that we probably misjudged CVE-2026-21637, on a second look it doesn't look like a vulnerability, rather than a bug. The user responsibility is to not throw in that event handler, it's user code so outside of our threat model.

If revoking CVEs is a thing, I suggest we do that so users can adjust their expectations.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions