Skip to content

[3.14] gh-143921: Reject NUL, CR and LF in IMAP commands (GH-143922, GH-153067) - #153137

Merged
serhiy-storchaka merged 1 commit into
python:3.14from
serhiy-storchaka:backport-ctl-chars-3.14
Jul 7, 2026
Merged

[3.14] gh-143921: Reject NUL, CR and LF in IMAP commands (GH-143922, GH-153067)#153137
serhiy-storchaka merged 1 commit into
python:3.14from
serhiy-storchaka:backport-ctl-chars-3.14

Conversation

@serhiy-storchaka

Copy link
Copy Markdown
Member

Combined backport of GH-143922, which rejected all control characters, and GH-153067, which narrowed the check to NUL, CR and LF. Other control characters are valid in quoted strings and are sent quoted (GH-152703, already backported).

(cherry picked from commit 6262704)
(cherry picked from commit d0921ef)

…nGH-143922, pythonGH-153067)

Combined backport of pythonGH-143922, which rejected all control characters,
and pythonGH-153067, which narrowed the check to NUL, CR and LF.  Other
control characters are valid in quoted strings and are sent quoted.

(cherry picked from commit 6262704)
(cherry picked from commit d0921ef)

Co-authored-by: Seth Michael Larson <seth@python.org>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@serhiy-storchaka
serhiy-storchaka merged commit 2981822 into python:3.14 Jul 7, 2026
55 checks passed
@miss-islington-app

Copy link
Copy Markdown

Thanks @serhiy-storchaka for the PR 🌮🎉.. I'm working now to backport this PR to: 3.13.
🐍🍒⛏🤖

@serhiy-storchaka
serhiy-storchaka deleted the backport-ctl-chars-3.14 branch July 7, 2026 17:13
@miss-islington-app

Copy link
Copy Markdown

Sorry, @serhiy-storchaka, I could not cleanly backport this to 3.13 due to a conflict.
Please backport using cherry_picker on command line.

cherry_picker 298182272a740ce2016aee2f54acbd0bba1944c1 3.13

@bedevere-app

bedevere-app Bot commented Jul 7, 2026

Copy link
Copy Markdown

GH-153287 is a backport of this pull request to the 3.13 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.13 bugs and security fixes label Jul 7, 2026
serhiy-storchaka added a commit that referenced this pull request Jul 7, 2026
…H-153067) (GH-153137) (GH-153287)

Combined backport of GH-143922, which rejected all control characters,
and GH-153067, which narrowed the check to NUL, CR and LF.  Other
control characters are valid in quoted strings and are sent quoted.

(cherry picked from commit 6262704)
(cherry picked from commit d0921ef)
(cherry picked from commit 2981822)

Co-authored-by: Seth Michael Larson <seth@python.org>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
tyler-rich added a commit to tyler-rich/Scrye that referenced this pull request Jul 26, 2026
…b backport landed on 3.14

Group B's rationale — upstream declined the backport to 3.10-3.14, so
these are fixed only in 3.15+ — is no longer true of CVE-2025-15366.
Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars
guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged
2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still
under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased,
closing on 3.14.7.

poplib is unchanged — its guard is on main only, and gh-143923 lists no
backport PR. The two diverged because imaplib's check was narrowed to
NUL/CR/LF (python/cpython#153067), clearing the regression concern behind
the original decline; poplib's still rejects the full control-character
range.

Group B keeps its standing-acceptance framing, its annual review date
(2027-07-25), and the do-not-scope-a-3.15-move instruction, now for
CVE-2025-15367 alone. The waiver list is unchanged at four entries.

The 2026-07-25 entry is superseded on this one point and left unedited;
its reading of 3.14.6 was correct, but the backport had already merged
18 days before it was written.

See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
tyler-rich added a commit to tyler-rich/Scrye that referenced this pull request Jul 26, 2026
…b backport landed on 3.14 (#100)

Group B's rationale — upstream declined the backport to 3.10-3.14, so
these are fixed only in 3.15+ — is no longer true of CVE-2025-15366.
Lib/imaplib.py on the 3.14 and 3.13 branches carries the _control_chars
guard in IMAP4._command() (python/cpython#153137, commit 2981822, merged
2026-07-07); v3.14.6 does not, and the gh-143921 NEWS entry is still
under Misc/NEWS.d/next/Security. That is Group A shape: merged, unreleased,
closing on 3.14.7.

poplib is unchanged — its guard is on main only, and gh-143923 lists no
backport PR. The two diverged because imaplib's check was narrowed to
NUL/CR/LF (python/cpython#153067), clearing the regression concern behind
the original decline; poplib's still rejects the full control-character
range.

Group B keeps its standing-acceptance framing, its annual review date
(2027-07-25), and the do-not-scope-a-3.15-move instruction, now for
CVE-2025-15367 alone. The waiver list is unchanged at four entries.

The 2026-07-25 entry is superseded on this one point and left unedited;
its reading of 3.14.6 was correct, but the backport had already merged
18 days before it was written.

See docs/ARCHIVE.md § Deviations (2026-07-26) for the evidence.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants