﻿id	summary	reporter	owner	description	type	status	component	version	severity	resolution	keywords	cc	stage	has_patch	needs_docs	needs_tests	needs_better_patch	easy	ui_ux
37414	Reject invalid characters in response header names and values	Natalia Bidart		"`ResponseHeaders._convert_to_charset()` only rejects CR and LF, so other characters that are invalid per [https://www.rfc-editor.org/rfc/rfc9110.html#section-5.5 RFC 9110 section 5.5] are sent as-is:

  Field values containing CR, LF, or NUL characters are invalid and dangerous [...] Field values containing other CTL characters are also invalid [...]

Field names must be `token` characters, which Django doesn't validate at all. For example:

{{{#!python
from django.conf import settings; settings.configure()
from django.http import HttpResponse

r = HttpResponse()
r[""X-Test""] = ""a\x00b""
r[""X-Test\x0b""] = ""1""
print(r.serialize_headers())
}}}

outputs:
{{{
b'Content-Type: text/html; charset=utf-8\r\nX-Test: a\x00b\r\nX-Test\x0b: 1'
}}}

Django could raise `django.http.BadHeaderError` for NUL and other C0 controls (except HTAB) and DEL in values, and for non-token characters in names, similar to what #37100 did for `reason_phrase`. Note that `_control_chars_re` can't be reused as is."	Cleanup/optimization	new	HTTP handling	dev	Normal		not-security		Accepted	0	0	0	0	0	0
