]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
[3.13] Added a warning to the urljoin docs, indicating that it is not safe to use...
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Fri, 15 Nov 2024 23:15:27 +0000 (00:15 +0100)
committerGitHub <noreply@github.com>
Fri, 15 Nov 2024 23:15:27 +0000 (23:15 +0000)
commitc8962104f2c8502b9a6b8a5e0f6603916852c13f
tree9a8550249c11a0ebd548a07a3d5c5de462a9fb03
parent7be8743bd120271a4e0101aa575d357b9962e809
[3.13] Added a warning to the urljoin docs, indicating that it is not safe to use with attacker controlled URLs (GH-126659) (#126888)

Added a warning to the urljoin docs, indicating that it is not safe to use with attacker controlled URLs (GH-126659)

This was flagged to me at a party today by someone who works in red-teaming as a frequently encountered footgun. Documenting the potentially unexpected behavior seemed like a good place to start.
(cherry picked from commit d6bcc154e93a0a20ab97187d3e8b726fffb14f8f)

Co-authored-by: Alex Gaynor <alex.gaynor@gmail.com>
Doc/library/urllib.parse.rst