Skip to content

[3.12] Added a warning to the urljoin docs, indicating that it is not safe to use with attacker controlled URLs (GH-126659) #126889

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Nov 15, 2024

Conversation

miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Nov 15, 2024

This was flagged to me at a party today by someone who works in red-teaming as a frequently encountered footgun. Documenting the potentially unexpected behavior seemed like a good place to start.
(cherry picked from commit d6bcc15)

Co-authored-by: Alex Gaynor [email protected]


📚 Documentation preview 📚: https://cpython-previews--126889.org.readthedocs.build/

…o use with attacker controlled URLs (pythonGH-126659)

This was flagged to me at a party today by someone who works in red-teaming as a frequently encountered footgun. Documenting the potentially unexpected behavior seemed like a good place to start.
(cherry picked from commit d6bcc15)

Co-authored-by: Alex Gaynor <[email protected]>
@bedevere-app bedevere-app bot added docs Documentation in the Doc dir skip news skip issue labels Nov 15, 2024
@Eclips4 Eclips4 enabled auto-merge (squash) November 15, 2024 23:11
@Eclips4 Eclips4 merged commit 797a632 into python:3.12 Nov 15, 2024
27 of 28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docs Documentation in the Doc dir skip issue skip news
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

3 participants