#2988: add note about catching CookieError when parsing untrusted cookie data.
diff --git a/Doc/library/cookie.rst b/Doc/library/cookie.rst
index aae7bc2..346da5a 100644
--- a/Doc/library/cookie.rst
+++ b/Doc/library/cookie.rst
@@ -22,6 +22,12 @@
 MSIE 3.0x doesn't follow the character rules outlined in those specs.  As a
 result, the parsing rules used are a bit less strict.
 
+.. note::
+
+   On encountering an invalid cookie, :exc:`CookieError` is raised, so if your
+   cookie data comes from a browser you should always prepare for invalid data
+   and catch :exc:`CookieError` on parsing.
+
 
 .. exception:: CookieError