)]}'
{
  "commit": "89ef3d95e781148a0951956029c92a211477f7f9",
  "tree": "3c1137b738e04271d6dd9246ef9fddf31de0af0b",
  "parents": [
    "85d9c07bbe3a33a875ef21b02f48ac405ad17d5f"
  ],
  "author": {
    "name": "Katie Hockman",
    "email": "katie@golang.org",
    "time": "Fri Apr 23 12:56:01 2021 -0400"
  },
  "committer": {
    "name": "Katie Hockman",
    "email": "katie@golang.org",
    "time": "Wed Apr 28 14:07:49 2021 +0000"
  },
  "message": "http/httpguts: remove recursion in HeaderValuesContainsToken\n\nPreviously, httpguts.HeaderValuesContainsToken called a\nfunction which could recurse to the point of a stack\noverflow when given a very large header (~10MB).\n\nCredit to Guido Vranken who reported the crash as\npart of the Ethereum 2.0 bounty program.\n\nFixes CVE-2021-31525\n\nFixes golang/go#45710\n\nChange-Id: I2c54ce3b2acf1c5efdea66db0595b93a3f5ae5f3\nReviewed-on: https://go-review.googlesource.com/c/net/+/313069\nTrust: Katie Hockman \u003ckatie@golang.org\u003e\nRun-TryBot: Katie Hockman \u003ckatie@golang.org\u003e\nTryBot-Result: Go Bot \u003cgobot@golang.org\u003e\nReviewed-by: Filippo Valsorda \u003cfilippo@golang.org\u003e\nReviewed-by: Roland Shoemaker \u003croland@golang.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "e7de24ee64efc6b10326616b2b5b2588b2b70439",
      "old_mode": 33188,
      "old_path": "http/httpguts/httplex.go",
      "new_id": "c79aa73f28bb9a522de0d653b01637083c631e85",
      "new_mode": 33188,
      "new_path": "http/httpguts/httplex.go"
    }
  ]
}
