Repository navigation
HTTP proxy via "CONNECT" tunneling doesn't sanitize CR/LF #146211
Copy link
Copy link
Closed
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-securityA security issueA security issue
on Mar 20, 2026 - added a commit that references this issue
on Mar 20, 2026 - addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixesand removedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Mar 20, 2026 - added 3 commits that reference this issue
on Apr 10, 2026 11 remaining items
- added a commit that references this issue
on Jun 22, 2026 - added a commit that references this issue
on Jun 24, 2026 - added a commit that references this issue
on Jul 5, 2026 - added a commit that references this issue
on Aug 14, 2026
Metadata
Metadata
Assignees
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
Bug report
Bug description:
HTTP proxy via "CONNECT" tunneling doesn't sanitize CR/LF. Should sanitize the input of
.set_tunnel()to avoid header splitting.CPython versions tested on:
CPython main branch
Operating systems tested on:
Other, Linux
Linked PRs