Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

[3.14] gh-143930: Reject leading dashes in webbrowser URLs#146214

Merged
ambv merged 1 commit into
python:3.14python/cpython:3.14from
miss-islington:backport-82a24a4-3.14miss-islington/cpython:backport-82a24a4-3.14Copy head branch name to clipboard
Mar 23, 2026
Merged

[3.14] gh-143930: Reject leading dashes in webbrowser URLs#146214
ambv merged 1 commit into
python:3.14python/cpython:3.14from
miss-islington:backport-82a24a4-3.14miss-islington/cpython:backport-82a24a4-3.14Copy head branch name to clipboard

Conversation

@miss-islington

@miss-islington miss-islington commented Mar 20, 2026

Copy link
Copy Markdown
Contributor

(cherry picked from commit 82a24a4)

Co-authored-by: Seth Michael Larson seth@python.org

(cherry picked from commit 82a24a4)

Co-authored-by: Seth Michael Larson <seth@python.org>
@ambv ambv merged commit 9669a91 into python:3.14 Mar 23, 2026
53 checks passed
@miss-islington miss-islington deleted the backport-82a24a4-3.14 branch March 23, 2026 23:16
hroncok pushed a commit to fedora-python/cpython that referenced this pull request Mar 26, 2026
Reject leading dashes in webbrowser URLs (pythonGH-146214)

(cherry picked from commit 82a24a4)

Co-authored-by: Seth Michael Larson <seth@python.org>
ihvo pushed a commit to ihvo/azurelinux that referenced this pull request Apr 24, 2026
Verified against python/cpython that every CVE patch on the 3.12 fork has a
3.14-branch backport PR that merged before 3.14.4's release on 2026-04-07:

  CVE-2026-0672 → PR python/cpython#144089 (merged 2026-01-23)
  CVE-2026-0865 → PRs python/cpython#143972 + #144761 (merged 2026-01-17 / 02-21)
  CVE-2026-1299 → PR python/cpython#144182 (merged 2026-01-25)
  CVE-2026-4519 → PRs python/cpython#146214 + #148042 (merged 2026-03-23 / 04-03)

The CVE-2025-* patches are even older and were already in 3.14.0 (GA 2025-10).
Carrying patches we don't need adds hunk-maintenance cost, rebase risk, and
auditor confusion with no upside.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Development

Successfully merging this pull request may close these issues.

3 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.