summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--Doc/library/http.server.rst6
1 files changed, 6 insertions, 0 deletions
diff --git a/Doc/library/http.server.rst b/Doc/library/http.server.rst
index bc59d3d..886e359 100644
--- a/Doc/library/http.server.rst
+++ b/Doc/library/http.server.rst
@@ -520,6 +520,12 @@ the ``--cgi`` option::
:mod:`http.server` command line ``--cgi`` support is being removed
because :class:`CGIHTTPRequestHandler` is being removed.
+.. warning::
+
+ :class:`CGIHTTPRequestHandler` and the ``--cgi`` command line option
+ are not intended for use by untrusted clients and may be vulnerable
+ to exploitation. Always use within a secure environment.
+
.. _http.server-security:
Security Considerations