1. Critical SSRF Bypass Discovered: Empty DNS Resolution Arrays Can Evade Private IP Validation
A security researcher has identified and patched a Server-Side Request Forgery (SSRF) vulnerability in affected codebases. The flaw exploited how JavaScript's `dns.lookup()` function handles domain resolution when a maliciously crafted domain returns an empty address array. By supplying such a domain, an attacker could...