Commit c4b17db
gh-142412: Add warning about urlsplit's netloc parsing and open redirects
Add a warning to the URL parsing security section explaining that
urlsplit/urlparse only parse the netloc when preceded by //. This
behavior can lead to open redirect vulnerabilities if applications
rely solely on checking the netloc to validate redirect URLs.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>1 parent 7e2c9bd commit c4b17db
1 file changed
+11
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
530 | 530 | | |
531 | 531 | | |
532 | 532 | | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
533 | 544 | | |
534 | 545 | | |
535 | 546 | | |
| |||
0 commit comments