A patch release adding a header-injection sink for response headers.
Features
- 🛡️ Report user-controlled response header values as
TaintedHeaderunder--taint-analysis: the$headersargument ofResponseFactory::make()(direct, contract, and facade forms), the three-argumentresponse()helper, andnew Response()is now aheadersink. The attachment exemption still applies only to theTaintedHtmlcontent finding (#1575)
$title = $request->input('team');
return response()->make($csv, 200, [
'Content-Disposition' => "attachment; filename=\"{$title}.csv\"",
]);
-// before: no issue
+// now: TaintedHeader: Detected tainted header- Recommend
alies-dev/psalm-plugin-pestinstead ofpsalm/plugin-phpunitinpsalm-laravel initwhen the project requirespestphp/pest(#1596)
Fixes
- Write the facade alias stub atomically, so overlapping Psalm runs on one project (IDE plus CLI, parallel CI steps) no longer read a truncated stub and fail with a parse error or a missing alias class (#1604)
Full Changelog: v3.16.3...v3.16.4