Took me a while, but here is the full article! If you want to see some weird URL parsing behavior, here you can find a lot of them :) sec.leonardini.dev/blog/playing... Disclaimer: no exploits nor vulnerabilities in this post, just some broken code
Playing with Bun's URL parser
During the latest SECCON CTF quals, I had the pleasure of reading the custom implementation of Bun's URL parser, and I found some... weird behaviors... Join me in this wonderful journey.
sec.leonardini.dev
Currenly playing around with Bun's URL parser, and I must say it's pretty fun. It's not vulnerable as it's never used raw, but expect a few GH issues and a blog post about it. Spoiling the least interesting quirk to keep you on your toes :) Hopefully I'm not ruining anybody's future challenge :')