[issue30500] [security] urllib connects to a wrong host

Serhiy Storchaka report at bugs.python.org
Tue Jun 20 10:11:19 EDT 2017


Serhiy Storchaka added the comment:

Oh, I didn't expected that newlines can be in a host name. In any case if newlines are a problem, it is better to check explicitly whether a host name contains CR, LF or other special characters. And it is better to do such checks when format a request rather than when parse an URL.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue30500>
_______________________________________


More information about the Python-bugs-list mailing list