Skip to content

gh-143921: Narrow the control character check in imaplib commands - #153067

Merged
serhiy-storchaka merged 1 commit into
python:mainfrom
serhiy-storchaka:imaplib-narrow-ctl-check
Jul 5, 2026
Merged

gh-143921: Narrow the control character check in imaplib commands#153067
serhiy-storchaka merged 1 commit into
python:mainfrom
serhiy-storchaka:imaplib-narrow-ctl-check

Conversation

@serhiy-storchaka

@serhiy-storchaka serhiy-storchaka commented Jul 5, 2026

Copy link
Copy Markdown
Member

The broad check rejected all of 0x00-0x1F and 0x7F, but only NUL, CR and LF are actually unsafe (command injection / binary truncation).
TAB and other control characters are valid QUOTED-CHARs per RFC 3501 and RFC 9051, and a mailbox name containing them can be returned by the server via LIST, so the client must be able to send it back in SELECT, STATUS, etc. Rejecting such names made imaplib unable to operate on a folder that legitimately exists.
Now that GH-152703 restored argument quoting, such arguments are sent as quoted strings; only NUL, CR and LF (which cannot be represented even in a quoted string) are still rejected.

🤖 Generated with Claude Code

Only NUL, CR and LF are rejected now.  Other control characters are
valid in quoted strings and can occur in mailbox names returned by
the server, so they are now accepted and sent quoted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@serhiy-storchaka
serhiy-storchaka requested a review from a team as a code owner July 5, 2026 06:27
@serhiy-storchaka serhiy-storchaka added the needs backport to 3.15 pre-release feature fixes, bugs and security fixes label Jul 5, 2026
@serhiy-storchaka
serhiy-storchaka merged commit d0921ef into python:main Jul 5, 2026
59 checks passed
@miss-islington-app

Copy link
Copy Markdown

Thanks @serhiy-storchaka for the PR 🌮🎉.. I'm working now to backport this PR to: 3.15.
🐍🍒⛏🤖

@bedevere-app

bedevere-app Bot commented Jul 5, 2026

Copy link
Copy Markdown

GH-153135 is a backport of this pull request to the 3.15 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.15 pre-release feature fixes, bugs and security fixes label Jul 5, 2026
serhiy-storchaka added a commit that referenced this pull request Jul 5, 2026
…nds (GH-153067) (GH-153135)

Only NUL, CR and LF are rejected now.  Other control characters are
valid in quoted strings and can occur in mailbox names returned by
the server, so they are now accepted and sent quoted.
(cherry picked from commit d0921ef)

Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
serhiy-storchaka added a commit that referenced this pull request Jul 7, 2026
…H-153067) (GH-153137)

Combined backport of GH-143922, which rejected all control characters,
and GH-153067, which narrowed the check to NUL, CR and LF.  Other
control characters are valid in quoted strings and are sent quoted.

(cherry picked from commit 6262704)
(cherry picked from commit d0921ef)

Co-authored-by: Seth Michael Larson <seth@python.org>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
serhiy-storchaka added a commit that referenced this pull request Jul 7, 2026
…H-153067) (GH-153137) (GH-153287)

Combined backport of GH-143922, which rejected all control characters,
and GH-153067, which narrowed the check to NUL, CR and LF.  Other
control characters are valid in quoted strings and are sent quoted.

(cherry picked from commit 6262704)
(cherry picked from commit d0921ef)
(cherry picked from commit 2981822)

Co-authored-by: Seth Michael Larson <seth@python.org>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@serhiy-storchaka
serhiy-storchaka deleted the imaplib-narrow-ctl-check branch July 15, 2026 11:50
tyler-rich added a commit to tyler-rich/Scrye that referenced this pull request Jul 26, 2026
…b backport landed on 3.14

Group B's rationale — upstream declined the backport to 3.10-3.14, so
these are fixed only in 3.15+ — is no longer true of CVE-2025-15366.
Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars
guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged
2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still
under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased,
closing on 3.14.7.

poplib is unchanged — its guard is on main only, and gh-143923 lists no
backport PR. The two diverged because imaplib's check was narrowed to
NUL/CR/LF (python/cpython#153067), clearing the regression concern behind
the original decline; poplib's still rejects the full control-character
range.

Group B keeps its standing-acceptance framing, its annual review date
(2027-07-25), and the do-not-scope-a-3.15-move instruction, now for
CVE-2025-15367 alone. The waiver list is unchanged at four entries.

The 2026-07-25 entry is superseded on this one point and left unedited;
its reading of 3.14.6 was correct, but the backport had already merged
18 days before it was written.

See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
tyler-rich added a commit to tyler-rich/Scrye that referenced this pull request Jul 26, 2026
…b backport landed on 3.14 (#100)

Group B's rationale — upstream declined the backport to 3.10-3.14, so
these are fixed only in 3.15+ — is no longer true of CVE-2025-15366.
Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars
guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged
2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still
under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased,
closing on 3.14.7.

poplib is unchanged — its guard is on main only, and gh-143923 lists no
backport PR. The two diverged because imaplib's check was narrowed to
NUL/CR/LF (python/cpython#153067), clearing the regression concern behind
the original decline; poplib's still rejects the full control-character
range.

Group B keeps its standing-acceptance framing, its annual review date
(2027-07-25), and the do-not-scope-a-3.15-move instruction, now for
CVE-2025-15367 alone. The waiver list is unchanged at four entries.

The 2026-07-25 entry is superseded on this one point and left unedited;
its reading of 3.14.6 was correct, but the backport had already merged
18 days before it was written.

See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants