Skip to content

Python implementation of json.loads() accepts invalid unicode escapes #125660

Description

@nineteendo

Bug report

Bug description:

While reviewing #125652 and reading the documentation of int(), I realised this condition in json.decoder is insufficient:

if len(esc) == 4 and esc[1] not in 'xX':

>>> import sys
>>> sys.modules["_json"] = None
>>> import json
>>> json.loads(r'["\u 000", "\u-000", "\u+000", "\u0_00"]')
['\x00', '\x00', '\x00', '\x00']

CPython versions tested on:

3.13

Operating systems tested on:

macOS

Linked PRs

Activity

  1. nineteendo commented on Oct 17, 2024

    @nineteendo
    ContributorAuthor
  2. nineteendo commented on Oct 17, 2024

    @nineteendo
    ContributorAuthor

    Maybe something like this? Although it might be a better idea to use a stricter function.

    esc = s[end:end + 4].strip()
    if "_" not in esc and len(esc) == 4 and esc[0] not in "+-" and esc[1] not in "xX":
  3. added
    stdlibStandard Library Python modules in the Lib/ directory
    on Oct 17, 2024
  4. serhiy-storchaka commented on Oct 17, 2024

    @serhiy-storchaka
    Member

    Either this, or simply use regexp.

  5. nineteendo commented on Oct 18, 2024

    @nineteendo
    ContributorAuthor

    Let's use a regex, unicode digits aren't allowed either:

    >>> int("\uff10", 16)
    0
  6. nineteendo commented on Oct 18, 2024

    @nineteendo
    ContributorAuthor

    Could there be other code that suffers from this problem?

  7. taleinat commented on Oct 18, 2024

    @taleinat
    Contributor

    Could there be other code that suffers from this problem?

    Possibly, but that's out of context for this issue. If someone finds such issues they should be reported separately.

  8. added a commit that references this issue on Oct 18, 2024
  9. added 2 commits that reference this issue on Oct 18, 2024
  10. added 3 commits that reference this issue on Oct 19, 2024
  11. added a commit that references this issue on Jan 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    stdlibStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or error

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions