Skip to main content

Telechat Review of draft-ietf-cellar-tags-25
review-ietf-cellar-tags-25-secdir-telechat-sethi-2026-05-03-00

Request Review of draft-ietf-cellar-tags
Requested revision No specific revision (document currently at 25)
Type Telechat Review
Team Security Area Directorate (secdir)
Deadline 2026-01-06
Requested 2025-12-08
Authors Steve Lhomme , Moritz Bunkus, Dave Rice
I-D last updated 2026-06-02 (Latest revision 2026-05-03)
Completed reviews Genart IETF Last Call review of -19 by Ines Robles (diff)
Secdir IETF Last Call review of -19 by Mohit Sethi (diff)
Artart IETF Last Call review of -19 by Sean Turner (diff)
Artart Telechat review of -20 by Sean Turner (diff)
Secdir Telechat review of -25 by Mohit Sethi
Assignment Reviewer Mohit Sethi
State Completed
Request Telechat review on draft-ietf-cellar-tags by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/ST0xpcLimAXp9I5-lsyEZuRVbCw
Reviewed revision 25
Result Ready
Completed 2026-05-03
review-ietf-cellar-tags-25-secdir-telechat-sethi-2026-05-03-00
I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These comments
were written primarily for the benefit of the security area directors. Document
editors and WG chairs should treat these comments just like any other last-call
comments.

Since the last reviewed version (-19), the authors have added other specific
vectors of security issues such as string parsing risks and URL handling.
Implementations must strictly validate TagString inputs for UTF-8 correctness
and reasonable length limits to prevent vulnerabilities when reading strings
as-is or parsing specific technical tags. The authors also highlight that tags
containing URLs could be spoofed or altered to direct users to malicious
destinations.