[1.172.0] — 2026-08-13
Fixed (MEDIUM, scanner) — a malformed HTML entity could crash a scan source (career-ops #2150 parity).
Fixed
- The
oraclecloud,gemanddassaultsources decoded numeric HTML entities with a bareNumber.isFiniteguard beforeString.fromCodePoint— a reference above0x10FFFF(e.g.�from a malformed or adversarial feed) threw an uncaughtRangeErrorand aborted that source's entire parse. A sharedserver/lib/html-entities.mjs(mirroring the parent's_html-entities.mjs) now restricts numeric references to the XML 1.0 §2.2 Char set soString.fromCodePointcan never throw, and matches hex vs decimal separately soa2;no longer mis-parses. The three sources import it.
Notes
- No change for valid feeds; no JS / i18n / route / CSP / SSRF / parent-write change. Consolidating the ~20 remaining in-source decoder copies is tracked in
qa/PARENT-SYNC-WORKLIST-v1.26.0.md. - Tests:
tests/html-entities.test.mjs(+7). Suite: 2444 (+7).