Hacker News new | ask | show | jobs
by jadamson 195 days ago
> The body parsing logic is in react or nextjs, that's my takeaway, is it that incorrect?

The exploit they were trying to protect against is in React services run by their customers.

1 comments

that makes better sense now, thanks. I feel dumb now that I re-read it, in my mind they patched nextjs/react and the new patch somehow required more buffer size.