From: Miss Islington (bot) <31488909+miss-islington@users.noreply.github.com> Date: Sat, 2 May 2026 11:13:57 +0000 (+0200) Subject: [3.13] gh-111264: Add a note about untrusted input to tomllib docs (#149226) X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=b2742046576487ccf20be9496fb74a476a6c5312;p=thirdparty%2FPython%2Fcpython.git [3.13] gh-111264: Add a note about untrusted input to tomllib docs (#149226) (cherry picked from commit 9d41e2a534aab460dd656ef251adaed5d2d64b93) Co-authored-by: Petr Viktorin Co-authored-by: Stan Ulbrych --- diff --git a/Doc/library/tomllib.rst b/Doc/library/tomllib.rst index 521a7a17fb3e..77555c0e4849 100644 --- a/Doc/library/tomllib.rst +++ b/Doc/library/tomllib.rst @@ -17,6 +17,13 @@ This module provides an interface for parsing TOML 1.0.0 (Tom's Obvious Minimal Language, `https://toml.io `_). This module does not support writing TOML. +.. warning:: + + Be cautious when parsing data from untrusted sources. + A malicious TOML string may cause the decoder to consume considerable + CPU and memory resources. + Limiting the size of data to be parsed is recommended. + .. seealso:: The :pypi:`Tomli-W package `