Description
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
Problem types
Product status
Any version before 3.13.12
3.14.0 (python) before 3.14.3
3.15.0a1 (python) before 3.15.0a6
Credits
Omar M. Hasan
References
github.com/python/cpython/pull/143926
github.com/python/cpython/issues/143925
mail.python.org/.../thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/
github.com/...ommit/f25509e78e8be6ea73c811ac2b8c928c28841b9f
github.com/...ommit/05356b1cc153108aaf27f3b72ce438af4aa218c0
github.com/...ommit/34d76b00dabde81a793bd06dd8ecb057838c4b38
github.com/...ommit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80
github.com/...ommit/4ed11d3cd288e6b90196a15c5a825a45d318fe47
github.com/...ommit/a35ca3be5842505dab74dc0b90b89cde0405017a