diff --git a/javascript/ql/src/change-notes/2025-11-26-response-default-content-type.md b/javascript/ql/src/change-notes/2025-11-26-response-default-content-type.md index e39d82695de..67ece0e5353 100644 --- a/javascript/ql/src/change-notes/2025-11-26-response-default-content-type.md +++ b/javascript/ql/src/change-notes/2025-11-26-response-default-content-type.md @@ -1,5 +1,5 @@ --- category: minorAnalysis --- -* `new Response(x)` is not longer seen as a reflected XSS sink when no `content-type` header +* `new Response(x)` is no longer seen as a reflected XSS sink when no `content-type` header is set, since the content type defaults to `text/plain`.