mirror of
https://github.com/python/cpython.git
synced 2026-05-06 04:37:33 -04:00
gh-111264: Add a note about untrusted input to tomllib docs (GH-146209)
Co-authored-by: Stan Ulbrych <stan@python.org>
This commit is contained in:
@@ -19,6 +19,12 @@ support writing TOML.
|
||||
Added TOML 1.1.0 support.
|
||||
See the :ref:`What's New <whatsnew315-tomllib-1-1-0>` for details.
|
||||
|
||||
.. warning::
|
||||
|
||||
Be cautious when parsing data from untrusted sources.
|
||||
A malicious TOML string may cause the decoder to consume considerable
|
||||
CPU and memory resources.
|
||||
Limiting the size of data to be parsed is recommended.
|
||||
|
||||
.. seealso::
|
||||
|
||||
|
||||
Reference in New Issue
Block a user