Skip to content

[3.11] gh-121284: Fix email address header folding with parsed encoded-word (GH-122754) - #131405

Merged
ambv merged 1 commit into
python:3.11from
miss-islington:backport-295b53d-3.11
Apr 3, 2025
Merged

[3.11] gh-121284: Fix email address header folding with parsed encoded-word (GH-122754)#131405
ambv merged 1 commit into
python:3.11from
miss-islington:backport-295b53d-3.11

Conversation

@miss-islington

@miss-islingtonmiss-islington commented Mar 18, 2025

Copy link
Copy Markdown
Contributor

Email generators using email.policy.default may convert an RFC 2047
encoded-word to unencoded form during header refolding. In a structured
header, this could allow 'specials' chars outside a quoted-string,
leading to invalid address headers and enabling spoofing. This change
ensures a parsed encoded-word that contains specials is kept as an
encoded-word while the header is refolded.

[Better fix from @bitdancer.]


(cherry picked from commit 295b53d)

Co-authored-by: Mike Edmunds medmunds@gmail.com
Co-authored-by: R David Murray rdmurray@bitdance.com
Co-authored-by: Petr Viktorin encukou@gmail.com

…-word (pythonGH-122754)
Email generators using email.policy.default may convert an RFC 2047
encoded-word to unencoded form during header refolding. In a structured
header, this could allow 'specials' chars outside a quoted-string,
leading to invalid address headers and enabling spoofing. This change
ensures a parsed encoded-word that contains specials is kept as an
encoded-word while the header is refolded.
[Better fix from @bitdancer.]
---------
(cherry picked from commit 295b53d)
Co-authored-by: Mike Edmunds <medmunds@gmail.com>
Co-authored-by: R David Murray <rdmurray@bitdance.com>
Co-authored-by: Petr Viktorin <encukou@gmail.com>
@ambv
ambv merged commit 0a66052 into python:3.11Apr 3, 2025
@miss-islington
miss-islington deleted the backport-295b53d-3.11 branch January 2, 2026 17:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

topic-emailtype-securityA security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@miss-islington@bitdancer@ambv@medmunds