diff options
author | Jason R. Coombs <jaraco@jaraco.com> | 2022-07-17 16:32:08 -0400 |
---|---|---|
committer | Jason R. Coombs <jaraco@jaraco.com> | 2022-07-17 16:32:08 -0400 |
commit | 72d94e3adf2786aaa723f3f1b5bf8a9b34f28332 (patch) | |
tree | 4bdb06600886a51de68b9059bb0c38883f4941f5 /CHANGES.rst | |
parent | 78331575dacb67eaabf3e645533f1d05b861f00d (diff) | |
download | cherrypy-git-72d94e3adf2786aaa723f3f1b5bf8a9b34f28332.tar.gz |
Update changelog. Ref #1974.
Diffstat (limited to 'CHANGES.rst')
-rw-r--r-- | CHANGES.rst | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/CHANGES.rst b/CHANGES.rst index 697d77ef..35b3f895 100644 --- a/CHANGES.rst +++ b/CHANGES.rst @@ -1,3 +1,12 @@ +v18.8.0 +------- + +* :issue:`1974`: Dangerous characters received in a host header + encoded using RFC 2047 are now elided by default. Currently, + dangerous characters are defined as CR and LF. The original + value is still available as ``cherrypy.request.headers['Host'].raw`` + if needed. + v18.7.0 ------- |