Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[3.12] gh-143935: Email preserve parens when folding comments (GH-143936)#144036

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
pablogsal merged 2 commits intopython:3.12frommiss-islington:backport-17d1490-3.12
Jan 26, 2026

Conversation

@miss-islington
Copy link
Contributor

@miss-islingtonmiss-islington commentedJan 19, 2026
edited by bedevere-appbot
Loading

Fix a bug in the folding of comments when flattening an email message
using a modern email policy. Comments consisting of a very long sequence of
non-foldable characters could trigger a forced line wrap that omitted the
required leading space on the continuation line, causing the remainder of
the comment to be interpreted as a new header field. This enabled header
injection with carefully crafted inputs.
(cherry picked from commit17d1490)

Co-authored-by: Seth Michael Larsonseth@python.org
Co-authored-by: Denis Ledouxdle@odoo.com

…H-143936)Fix a bug in the folding of comments when flattening an email messageusing a modern email policy. Comments consisting of a very long sequence ofnon-foldable characters could trigger a forced line wrap that omitted therequired leading space on the continuation line, causing the remainder ofthe comment to be interpreted as a new header field. This enabled headerinjection with carefully crafted inputs.(cherry picked from commit17d1490)Co-authored-by: Seth Michael Larson <seth@python.org>Co-authored-by: Denis Ledoux <dle@odoo.com>
Copy link
Member

@pablogsalpablogsal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

LGTM

@pablogsalpablogsalenabled auto-merge (squash)January 25, 2026 17:11
@pablogsalpablogsal merged commita76e4cd intopython:3.12Jan 26, 2026
47 of 49 checks passed
@miss-islingtonmiss-islington deleted the backport-17d1490-3.12 branchJanuary 26, 2026 17:16
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@pablogsalpablogsalpablogsal left review comments

Assignees

No one assigned

Labels

topic-emailtype-securityA security issue

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

3 participants

@miss-islington@pablogsal@sethmlarson

[8]ページ先頭

©2009-2026 Movatter.jp