]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
bpo-39603: Prevent header injection in http methods (GH-18485)
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Sat, 18 Jul 2020 20:41:55 +0000 (13:41 -0700)
committerGitHub <noreply@github.com>
Sat, 18 Jul 2020 20:41:55 +0000 (13:41 -0700)
commit27b811057ff5e93b68798e278c88358123efdc71
tree14a2e7e3ae4b8e17e8e577d9c503d18920f89f4b
parentf92544483fc724b7e9ac11b2ee86b38e069cc70f
bpo-39603: Prevent header injection in http methods (GH-18485)

reject control chars in http method in http.client.putrequest to prevent http header injection
(cherry picked from commit 8ca8a2e8fb068863c1138f07e3098478ef8be12e)

Co-authored-by: AMIR <31338382+amiremohamadi@users.noreply.github.com>
Lib/http/client.py
Lib/test/test_httplib.py
Misc/NEWS.d/next/Security/2020-02-12-14-17-39.bpo-39603.Gt3RSg.rst [new file with mode: 0644]