Repository navigation
Python implementation of json.loads() accepts invalid unicode escapes #125660
Copy link
Copy link
Closed
Labels
stdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Oct 17, 2024 Maybe something like this? Although it might be a better idea to use a stricter function.
esc = s[end:end + 4].strip() if "_" not in esc and len(esc) == 4 and esc[0] not in "+-" and esc[1] not in "xX":
- addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Oct 17, 2024 Either this, or simply use regexp.
Let's use a regex, unicode digits aren't allowed either:
>>> int("\uff10", 16) 0
Could there be other code that suffers from this problem?
Could there be other code that suffers from this problem?
Possibly, but that's out of context for this issue. If someone finds such issues they should be reported separately.
- added a commit that references this issue
on Oct 18, 2024 - added 3 commits that reference this issue
on Oct 19, 2024
Metadata
Metadata
Assignees
Labels
stdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Projects
- StatusShow more project fieldsDone
Bug report
Bug description:
While reviewing #125652 and reading the documentation of
int(), I realised this condition injson.decoderis insufficient:cpython/Lib/json/decoder.py
Line 61 in f203d1c
CPython versions tested on:
3.13
Operating systems tested on:
macOS
Linked PRs
json.loads()accepts invalid unicode escapes #125683