gh-143921: Narrow the control character check in imaplib commands - #153067
Merged
serhiy-storchaka merged 1 commit intoJul 5, 2026
Merged
Conversation
Only NUL, CR and LF are rejected now. Other control characters are valid in quoted strings and can occur in mailbox names returned by the server, so they are now accepted and sent quoted. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
sethmlarson
approved these changes
Jul 5, 2026
|
Thanks @serhiy-storchaka for the PR 🌮🎉.. I'm working now to backport this PR to: 3.15. |
|
GH-153135 is a backport of this pull request to the 3.15 branch. |
serhiy-storchaka
added a commit
that referenced
this pull request
Jul 5, 2026
…nds (GH-153067) (GH-153135) Only NUL, CR and LF are rejected now. Other control characters are valid in quoted strings and can occur in mailbox names returned by the server, so they are now accepted and sent quoted. (cherry picked from commit d0921ef) Co-authored-by: Serhiy Storchaka <storchaka@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
serhiy-storchaka
added a commit
that referenced
this pull request
Jul 7, 2026
…H-153067) (GH-153137) Combined backport of GH-143922, which rejected all control characters, and GH-153067, which narrowed the check to NUL, CR and LF. Other control characters are valid in quoted strings and are sent quoted. (cherry picked from commit 6262704) (cherry picked from commit d0921ef) Co-authored-by: Seth Michael Larson <seth@python.org> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
serhiy-storchaka
added a commit
that referenced
this pull request
Jul 7, 2026
…H-153067) (GH-153137) (GH-153287) Combined backport of GH-143922, which rejected all control characters, and GH-153067, which narrowed the check to NUL, CR and LF. Other control characters are valid in quoted strings and are sent quoted. (cherry picked from commit 6262704) (cherry picked from commit d0921ef) (cherry picked from commit 2981822) Co-authored-by: Seth Michael Larson <seth@python.org> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This was referenced Jul 26, 2026
tyler-rich
added a commit
to tyler-rich/Scrye
that referenced
this pull request
Jul 26, 2026
…b backport landed on 3.14 Group B's rationale — upstream declined the backport to 3.10-3.14, so these are fixed only in 3.15+ — is no longer true of CVE-2025-15366. Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged 2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased, closing on 3.14.7. poplib is unchanged — its guard is on main only, and gh-143923 lists no backport PR. The two diverged because imaplib's check was narrowed to NUL/CR/LF (python/cpython#153067), clearing the regression concern behind the original decline; poplib's still rejects the full control-character range. Group B keeps its standing-acceptance framing, its annual review date (2027-07-25), and the do-not-scope-a-3.15-move instruction, now for CVE-2025-15367 alone. The waiver list is unchanged at four entries. The 2026-07-25 entry is superseded on this one point and left unedited; its reading of 3.14.6 was correct, but the backport had already merged 18 days before it was written. See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
tyler-rich
added a commit
to tyler-rich/Scrye
that referenced
this pull request
Jul 26, 2026
…b backport landed on 3.14 (#100) Group B's rationale — upstream declined the backport to 3.10-3.14, so these are fixed only in 3.15+ — is no longer true of CVE-2025-15366. Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged 2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased, closing on 3.14.7. poplib is unchanged — its guard is on main only, and gh-143923 lists no backport PR. The two diverged because imaplib's check was narrowed to NUL/CR/LF (python/cpython#153067), clearing the regression concern behind the original decline; poplib's still rejects the full control-character range. Group B keeps its standing-acceptance framing, its annual review date (2027-07-25), and the do-not-scope-a-3.15-move instruction, now for CVE-2025-15367 alone. The waiver list is unchanged at four entries. The 2026-07-25 entry is superseded on this one point and left unedited; its reading of 3.14.6 was correct, but the backport had already merged 18 days before it was written. See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The broad check rejected all of 0x00-0x1F and 0x7F, but only NUL, CR and LF are actually unsafe (command injection / binary truncation).
TAB and other control characters are valid QUOTED-CHARs per RFC 3501 and RFC 9051, and a mailbox name containing them can be returned by the server via LIST, so the client must be able to send it back in SELECT, STATUS, etc. Rejecting such names made imaplib unable to operate on a folder that legitimately exists.
Now that GH-152703 restored argument quoting, such arguments are sent as quoted strings; only NUL, CR and LF (which cannot be represented even in a quoted string) are still rejected.
🤖 Generated with Claude Code