active_url validation check bypass in Laravel

Reported and fixed a vulnerability in Laravel where active_url validation rule could be bypassed in a situation where a target has a subdomain localhost.
  • Posted on: 2021-06-12 14:36
  • Reading Time: 0 min
  • Share on:
    Y Combinator
    Reddit
    Mastodon

References