Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
{ "binaries": [ { "binary_name": "lynx", "binary_version": "2.8.9dev8-4ubuntu1+esm2" }, { "binary_name": "lynx-common", "binary_version": "2.8.9dev8-4ubuntu1+esm2" }, { "binary_name": "lynx-cur", "binary_version": "2.8.9dev8-4ubuntu1+esm2" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }