Full Disclosure Re: [oss-security] CVE request:Lynx invalid URL parsing with '?' November 5, 2016 007admin Leave a comment Posted by Michal Zalewski on Nov 05 IIRC, RFC 3986 “fixes” that, and so does https://url.spec.whatwg.org/. /mz