Repository navigation
Prep 4.18.2 release - #3066
Merged
Merged
Prep 4.18.2 release#3066
Conversation
* SECBUG-4278 Don't decode percent-encoded delimiters in URI hosts _validate_uri and _parse_srv both called unquote_plus on the whole host section before splitting it into individual host:port entries. A percent-encoded "," or ":" in an attacker-influenced hostname fragment therefore decoded into a real delimiter, injecting an extra, attacker-chosen host and port into the seed list on every parse. Move the percent-decoding into split_hosts and apply it only to Unix domain socket paths (identified by their unescaped ".sock" suffix before decoding), the only host identifiers that legitimately need it, and only after splitting on ",". * PYTHON-5986 Reject percent-encoded hostnames, preserve IPv6 zone indexes An IPv6 zone index is escaped as %25 (RFC 6874), so sockets are not the only host identifier that legitimately requires decoding; decode those too. Any other percent-encoding in a hostname is now rejected with InvalidURI rather than passed through as an unresolvable host. * PYTHON-5986 Address review feedback on test names and comments * PYTHON-5986 Simplify test comments * PYTHON-5986 Remove changelog entry
* SECBUG-4279 Reject Unix domain socket KMS endpoints _EncryptionIO.kms_request passed the KMS endpoint from a data key's masterKey.endpoint verbatim to parse_host(), which returns strings ending in ".sock" unchanged, bypassing hostname/port validation. _create_connection then treats any address ending in ".sock" as a Unix domain socket path and connects to it with AF_UNIX. Since masterKey.endpoint is read back from the key vault on every KMS request, a party able to write a key vault document could redirect the driver's KMS connection to an arbitrary local socket on the application host. Reject ".sock"-suffixed KMS endpoints immediately after parsing, before any connection is attempted. * PYTHON-5990 Drop spec test number from non-spec test name * PYTHON-5990 Drop duplicated comment from kms_request guard * PYTHON-5990 Reference PYTHON ticket in test and neutralize changelog wording * PYTHON-5990 Remove changelog entry
* PYTHON-5996 Harden bson buffer size guard against signed integer overflow * PYTHON-5996 Add changelog entry * remove changelog entry for now * Update doc/changelog.rst * Update doc/changelog.rst * Update doc/changelog.rst * Update doc/changelog.rst
blink1073
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PYTHON-XXXX
Changes in this PR
Test Plan
Checklist
Checklist for Author
Checklist for Reviewer