]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
bpo-39603: Prevent header injection in http methods (GH-18485)
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Sat, 18 Jul 2020 20:39:12 +0000 (13:39 -0700)
committerGitHub <noreply@github.com>
Sat, 18 Jul 2020 20:39:12 +0000 (13:39 -0700)
commit668d321476d974c4f51476b33aaca870272523bf
tree0d782398341a42ce2120382fe5068b5177d301d3
parent7734738d71c052779d3cb189e5ba0759beb8d620
bpo-39603: Prevent header injection in http methods (GH-18485)

reject control chars in http method in http.client.putrequest to prevent http header injection
(cherry picked from commit 8ca8a2e8fb068863c1138f07e3098478ef8be12e)

Co-authored-by: AMIR <31338382+amiremohamadi@users.noreply.github.com>
Lib/http/client.py
Lib/test/test_httplib.py
Misc/NEWS.d/next/Security/2020-02-12-14-17-39.bpo-39603.Gt3RSg.rst [new file with mode: 0644]