• Senthil Kumaran's avatar
    Prevent HTTPoxy attack (CVE-2016-1000110) · 5e070041
    Senthil Kumaran authored
    Ignore the HTTP_PROXY variable when REQUEST_METHOD environment is set, which
    indicates that the script is in CGI mode.
    
    Issue #27568 Reported and patch contributed by Rémi Rampin.
    5e070041
urllib.request.rst 54.2 KB