{"version": "https://jsonfeed.org/version/1", "title": "/dev/posts/ - Tag index - websub", "home_page_url": "https://www.gabriel.urdhr.fr", "feed_url": "/tags/websub/feed.json", "items": [{"id": "http://www.gabriel.urdhr.fr/2026/06/03/websub-reflected-xss/", "title": "Risk of reflected cross site scripting and Content-Security-Policy bypass in the WebSub intent verification", "url": "https://www.gabriel.urdhr.fr/2026/06/03/websub-reflected-xss/", "date_published": "2026-06-03T00:00:00+02:00", "date_modified": "2026-06-20T13:23:01+02:00", "tags": ["computer", "web", "websub", "security", "xss"], "content_html": "<p>I was reading the <a href=\"https://www.w3.org/TR/2018/REC-websub-20180123/\">WebSub</a> specification\n(formerly <a href=\"https://pubsubhubbub.github.io/PubSubHubbub/pubsubhubbub-core-0.4.html\">PubSubHubbub</a>)\nwhen I found that there was a <a href=\"https://github.com/w3c/websub/security/advisories/GHSA-f4hw-w632-m6wh\">risk of reflected browser-side code injection</a>\n(reflected <a href=\"https://owasp.org/www-community/attacks/xss/\">cross site scripting</a>, reflected XSS)\nin the WebSub intent verification exchange.</p>\n"}, {"id": "http://www.gabriel.urdhr.fr/2024/10/22/websub-sequence-diagram/", "title": "WebSub sequence diagram", "url": "https://www.gabriel.urdhr.fr/2024/10/22/websub-sequence-diagram/", "date_published": "2024-10-22T00:00:00+02:00", "date_modified": "2026-06-03T08:47:29+02:00", "tags": ["computer", "web", "websub"], "content_html": "<p>A sequence diagram for <a href=\"https://www.w3.org/TR/websub/\">WebSub</a> (formerly PubSubHubbub).</p>\n"}]}