#2988: add note about catching CookieError when parsing untrusted cookie data.
diff --git a/Doc/library/cookie.rst b/Doc/library/cookie.rst
index aae7bc2..346da5a 100644
--- a/Doc/library/cookie.rst
+++ b/Doc/library/cookie.rst
@@ -22,6 +22,12 @@
MSIE 3.0x doesn't follow the character rules outlined in those specs. As a
result, the parsing rules used are a bit less strict.
+.. note::
+
+ On encountering an invalid cookie, :exc:`CookieError` is raised, so if your
+ cookie data comes from a browser you should always prepare for invalid data
+ and catch :exc:`CookieError` on parsing.
+
.. exception:: CookieError