summaryrefslogtreecommitdiffstats
path: root/Misc/NEWS.d/next/Security/2019-04-10-08-53-30.bpo-36276.51E-DA.rst
blob: 4fed4d545040e9caf05b13bcd4c9c22c987649fb (plain)
1
Address CVE-2019-9740 by disallowing URL paths with embedded whitespace or control characters through into the underlying http client request.  Such potentially malicious header injection URLs now cause a ValueError to be raised.