Repository navigation
Document the security of tomllib for untrusted input #111264
Copy link
Copy link
Closed
Labels
3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixesdocsDocumentation in the Doc dirDocumentation in the Doc dirtype-securityA security issueA security issue
Description
Activity
In PR #96499
jsondocs added the warningWarning Be cautious when parsing JSON data from untrusted sources. A malicious JSON string may cause the decoder to consume considerable CPU and memory resources. Limiting the size of data to be parsed is recommended.as response to CVE-2020-10735 (cpython issue #95778).
The countermeasures already exist in v3.11.0 where
tomllibfirst appears so it's not vulnerable to that particular threat at least.Reacted by Pradyun Gedam- added3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes
on Mar 18, 2026 Let's add a similar note. Perhaps not as a warning -- it's more about communicating what to worry about when dealing with untrusted data (it might make the fan spin but won't format your disk), but also a reminder that you should think about how trusted your data is, plus a basic precaution.
- added a commit that references this issue
on May 1, 2026 - added a commit that references this issue
on May 2, 2026
Metadata
Metadata
Assignees
Labels
3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixesdocsDocumentation in the Doc dirDocumentation in the Doc dirtype-securityA security issueA security issue
Projects
- StatusShow more project fieldsTodo
Documentation
The documentation for tomllib should be explicit on whether untrusted input is safe to parse, or what features should be avoided.
Linked PRs