Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. (CVE-2021-38165)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2021-0422.json"