[3.13] gh-111264: Add a note about untrusted input to tomllib docs (#149226)

(cherry picked from commit 9d41e2a534)

Co-authored-by: Petr Viktorin <encukou@gmail.com>
Co-authored-by: Stan Ulbrych <stan@python.org>
This commit is contained in:
Miss Islington (bot)
2026-05-02 13:13:57 +02:00
committed by GitHub
parent 302ef2122c
commit b274204657
+7
View File
@@ -17,6 +17,13 @@ This module provides an interface for parsing TOML 1.0.0 (Tom's Obvious Minimal
Language, `https://toml.io <https://toml.io/en/>`_). This module does not
support writing TOML.
.. warning::
Be cautious when parsing data from untrusted sources.
A malicious TOML string may cause the decoder to consume considerable
CPU and memory resources.
Limiting the size of data to be parsed is recommended.
.. seealso::
The :pypi:`Tomli-W package <tomli-w>`