summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSenthil Kumaran <senthil@uthcode.com>2021-05-20 13:15:01 -0700
committerGitHub <noreply@github.com>2021-05-20 16:15:01 -0400
commitc723d5191110f99849f7b0944820f6c3cd5f7747 (patch)
treef4c604da2b68412d72222f9c5782c1e1cfa45f5b
parent1beae7e523d2db4e3ce383b2032095ef956f21c4 (diff)
downloadcpython-git-c723d5191110f99849f7b0944820f6c3cd5f7747.tar.gz
[3.7] bpo-43882 - Mention urllib.parse changes in Whats New section for 3.7.11 (GH-26267)
Co-authored-by: Gregory P. Smith <greg@krypto.org>
-rw-r--r--Doc/whatsnew/3.7.rst10
1 files changed, 10 insertions, 0 deletions
diff --git a/Doc/whatsnew/3.7.rst b/Doc/whatsnew/3.7.rst
index 85f924b2e4..2cc380bf5a 100644
--- a/Doc/whatsnew/3.7.rst
+++ b/Doc/whatsnew/3.7.rst
@@ -2594,3 +2594,13 @@ IPv4 address sent from the remote server when setting up a passive data
channel. We reuse the ftp server IP address instead. For unusual code
requiring the old behavior, set a ``trust_server_pasv_ipv4_address``
attribute on your FTP instance to ``True``. (See :issue:`43285`)
+
+
+The presence of newline or tab characters in parts of a URL allows for some
+forms of attacks. Following the WHATWG specification that updates RFC 3986,
+ASCII newline ``\n``, ``\r`` and tab ``\t`` characters are stripped from the
+URL by the parser :func:`urllib.parse` preventing such attacks. The removal
+characters are controlled by a new module level variable
+``urllib.parse._UNSAFE_URL_BYTES_TO_REMOVE``. (See :issue:`43882`)
+
+