Any plans to issue a CVE for this HTTP request smuggling attack vector fixed in the latest bun release?
Surprisingly, they appear to have not disclosed any vulnerabilities whatsoever. It's likely there have been numerous vulnerabilities in the past, but they are all being ignored.