Add change note.

This commit is contained in:
Owen Mansel-Chan
2025-09-30 12:35:03 +01:00
parent a2a9575587
commit dd3f754cb3

View File

@@ -0,0 +1,4 @@
---
category: minorAnalysis
---
* `go/unvalidated-url-redirection` and `go/request-forgery` have a shared notion of a safe URL, which is known to not be malicious. Some URLs which were incorrectly considered safe are now correctly considered unsafe. This may lead to more alerts for those two queries.