| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Only NUL, CR and LF are rejected now. Other control characters are valid in quoted strings and can occur in mailbox names returned by the server, so they are now accepted and sent quoted. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Thanks @serhiy-storchaka for the PR 🌮🎉.. I'm working now to backport this PR to: 3.15. |
Sorry, something went wrong.
|
GH-153135 is a backport of this pull request to the 3.15 branch. |
Sorry, something went wrong.
…nds (GH-153067) (GH-153135) Only NUL, CR and LF are rejected now. Other control characters are valid in quoted strings and can occur in mailbox names returned by the server, so they are now accepted and sent quoted. (cherry picked from commit d0921ef) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…H-153067) (GH-153137) Combined backport of GH-143922, which rejected all control characters, and GH-153067, which narrowed the check to NUL, CR and LF. Other control characters are valid in quoted strings and are sent quoted. (cherry picked from commit 6262704) (cherry picked from commit d0921ef) Co-authored-by: Seth Michael Larson <seth@python.org> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…H-153067) (GH-153137) (GH-153287) Combined backport of GH-143922, which rejected all control characters, and GH-153067, which narrowed the check to NUL, CR and LF. Other control characters are valid in quoted strings and are sent quoted. (cherry picked from commit 6262704) (cherry picked from commit d0921ef) (cherry picked from commit 2981822) Co-authored-by: Seth Michael Larson <seth@python.org> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…b backport landed on 3.14 Group B's rationale — upstream declined the backport to 3.10-3.14, so these are fixed only in 3.15+ — is no longer true of CVE-2025-15366. Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged 2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased, closing on 3.14.7. poplib is unchanged — its guard is on main only, and gh-143923 lists no backport PR. The two diverged because imaplib's check was narrowed to NUL/CR/LF (python/cpython#153067), clearing the regression concern behind the original decline; poplib's still rejects the full control-character range. Group B keeps its standing-acceptance framing, its annual review date (2027-07-25), and the do-not-scope-a-3.15-move instruction, now for CVE-2025-15367 alone. The waiver list is unchanged at four entries. The 2026-07-25 entry is superseded on this one point and left unedited; its reading of 3.14.6 was correct, but the backport had already merged 18 days before it was written. See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
…b backport landed on 3.14 (#100) Group B's rationale — upstream declined the backport to 3.10-3.14, so these are fixed only in 3.15+ — is no longer true of CVE-2025-15366. Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged 2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased, closing on 3.14.7. poplib is unchanged — its guard is on main only, and gh-143923 lists no backport PR. The two diverged because imaplib's check was narrowed to NUL/CR/LF (python/cpython#153067), clearing the regression concern behind the original decline; poplib's still rejects the full control-character range. Group B keeps its standing-acceptance framing, its annual review date (2027-07-25), and the do-not-scope-a-3.15-move instruction, now for CVE-2025-15367 alone. The waiver list is unchanged at four entries. The 2026-07-25 entry is superseded on this one point and left unedited; its reading of 3.14.6 was correct, but the backport had already merged 18 days before it was written. See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
| Back | FazBrowse Home | New Git URL |
The broad check rejected all of 0x00-0x1F and 0x7F, but only NUL, CR and LF are actually unsafe (command injection / binary truncation).
TAB and other control characters are valid QUOTED-CHARs per RFC 3501 and RFC 9051, and a mailbox name containing them can be returned by the server via LIST, so the client must be able to send it back in SELECT, STATUS, etc. Rejecting such names made imaplib unable to operate on a folder that legitimately exists.
Now that GH-152703 restored argument quoting, such arguments are sent as quoted strings; only NUL, CR and LF (which cannot be represented even in a quoted string) are still rejected.
🤖 Generated with Claude Code