CVE-2016-15039: Xhr Manual Content Lengthcve-2016-15039-xhr-manual-content-length
Manually setting the `Content-Length` header on an XMLHttpRequest is unsafe and forbidden by the W3C specification. Calculating the body length manually (e.g., using string `.length` which calculates character count, not byte count) results in an incorrect header value if the payload contains multi-byte characters. This manipulation enables HTTP Request Smug