JS: Change note

This commit is contained in:
Asger F
2025-11-26 13:34:16 +01:00
parent cc7bf4e880
commit 818f4815dd

View File

@@ -0,0 +1,5 @@
---
category: minorAnalysis
---
* `new Response(x)` is not longer seen as a reflected XSS sink when no`content-type` header
is set, since the content type defaults to `text/plain`.