commit | c4e671eec20dfcb29b18596a89ef075f826c9f96 | [log] [tgz] |
---|---|---|
author | Gregory P. Smith <greg@krypto.org> | Tue Apr 30 19:12:21 2019 -0700 |
committer | GitHub <noreply@github.com> | Tue Apr 30 19:12:21 2019 -0700 |
tree | ed97dd046a1467e029caed8416ed6de7182ef53a | |
parent | 5f38b8407b071acd96da2c8cde411d0e26967735 [diff] |
bpo-30458: Disallow control chars in http URLs. (GH-12755) Disallow control chars in http URLs in urllib.urlopen. This addresses a potential security problem for applications that do not sanity check their URLs where http request headers could be injected.