Sitelet https://github.com/python/cpython/issues/111264
Skip to content

Document the security of tomllib for untrusted input #111264

Description

Activity

  1. added
    docsDocumentation in the Doc dir
    on Oct 24, 2023
  2. hukkin commented on Oct 10, 2024

    @hukkin
    Contributor

    In PR #96499 json docs added the warning

    Warning
    Be cautious when parsing JSON data from untrusted sources. A malicious JSON string may cause
    the decoder to consume considerable CPU and memory resources. Limiting the size of data to be parsed is
    recommended. 
    

    as response to CVE-2020-10735 (cpython issue #95778).

    The countermeasures already exist in v3.11.0 where tomllib first appears so it's not vulnerable to that particular threat at least.

  3. added
    3.11only security fixes
    3.12only security fixes
    3.13only security fixes
    3.14bugs and security fixes
    3.15pre-release feature fixes, bugs and security fixes
    on Mar 18, 2026
  4. encukou commented on Mar 20, 2026

    @encukou
    Member

    Let's add a similar note. Perhaps not as a warning -- it's more about communicating what to worry about when dealing with untrusted data (it might make the fan spin but won't format your disk), but also a reminder that you should think about how trusted your data is, plus a basic precaution.

  5. added a commit that references this issue on Mar 20, 2026
  6. added a commit that references this issue on Apr 30, 2026
  7. added a commit that references this issue on May 1, 2026
  8. added a commit that references this issue on May 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.11only security fixes3.12only security fixes3.13only security fixes3.14bugs and security fixes3.15pre-release feature fixes, bugs and security fixesdocsDocumentation in the Doc dirtype-securityA security issue

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions