§13.9.

Logging of Untrusted String Fields

draft-20 · View on IETF ↗

The Reason Phrase (Section 1.4.4) and MOQT_IMPLEMENTATION option (Section 10.3.1.5) carry sender-controlled text that is commonly written to logs. Even though these fields are UTF-8 encoded, an endpoint that logs or renders them SHOULD sanitize them first (for example, by escaping bytes outside the printable ASCII range), since unsanitized values can enable log injection or terminal escape sequence injection.

This is one section of the MoQT specification, rendered per-section for quick reference and citation. The authoritative text is draft-ietf-moq-transport-20 at the IETF.