Team Ai
Apppublic

parthtamu/rag-code-assistant

sourceHugging Faceupdated 7mo agoView on Hugging Face
0likes
security_warnings.html371 linesDownload Raw Back to docs
1<!DOCTYPE html>2 3<html lang="en" data-content_root="../">4  <head>5    <meta charset="utf-8" />6    <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />7<meta property="og:title" content="Security Considerations" />8<meta property="og:type" content="website" />9<meta property="og:url" content="https://docs.python.org/3/library/security_warnings.html" />10<meta property="og:site_name" content="Python documentation" />11<meta property="og:description" content="The following modules have specific security considerations: base64: base64 security considerations in RFC 4648, hashlib: all constructors take a “usedforsecurity” keyword-only argument disabling k..." />12<meta property="og:image:width" content="1146" />13<meta property="og:image:height" content="600" />14<meta property="og:image" content="https://docs.python.org/3.15/_images/social_previews/summary_library_security_warnings_0b5bba50.png" />15<meta property="og:image:alt" content="The following modules have specific security considerations: base64: base64 security considerations in RFC 4648, hashlib: all constructors take a “usedforsecurity” keyword-only argument disabling k..." />16<meta name="description" content="The following modules have specific security considerations: base64: base64 security considerations in RFC 4648, hashlib: all constructors take a “usedforsecurity” keyword-only argument disabling k..." />17<meta name="twitter:card" content="summary_large_image" />18<meta name="theme-color" content="#3776ab">19 20    <title>Security Considerations &#8212; Python 3.15.0a6 documentation</title><meta name="viewport" content="width=device-width, initial-scale=1.0">21    22    <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=b86133f3" />23    <link rel="stylesheet" type="text/css" href="../_static/classic.css?v=234b1a7c" />24    <link rel="stylesheet" type="text/css" href="../_static/pydoctheme.css?v=89a2f22a" />25    <link rel="stylesheet" type="text/css" href="../_static/profiling-sampling-visualization.css?v=0c2600ae" />26    <link id="pygments_dark_css" media="(prefers-color-scheme: dark)" rel="stylesheet" type="text/css" href="../_static/pygments_dark.css?v=5349f25f" />27    28    <script src="../_static/documentation_options.js?v=6b7c9ff5"></script>29    <script src="../_static/doctools.js?v=9bcbadda"></script>30    <script src="../_static/sphinx_highlight.js?v=dc90522c"></script>31    <script src="../_static/profiling-sampling-visualization.js?v=9811ed04"></script>32    33    <script src="../_static/sidebar.js"></script>34    35    <link rel="search" type="application/opensearchdescription+xml"36          title="Search within Python 3.15.0a6 documentation"37          href="../_static/opensearch.xml"/>38    <link rel="author" title="About these documents" href="../about.html" />39    <link rel="index" title="Index" href="../genindex.html" />40    <link rel="search" title="Search" href="../search.html" />41    <link rel="copyright" title="Copyright" href="../copyright.html" />42    <link rel="next" title="Extending and Embedding the Python Interpreter" href="../extending/index.html" />43    <link rel="prev" title="xdrlib — Encode and decode XDR data" href="xdrlib.html" />44    45      46      <script defer file-types="bz2,epub,zip" data-domain="docs.python.org" src="https://analytics.python.org/js/script.file-downloads.outbound-links.js"></script>47      48      <link rel="canonical" href="https://docs.python.org/3/library/security_warnings.html">49      50    51 52    53    <style>54      @media only screen {55        table.full-width-table {56            width: 100%;57        }58      }59    </style>60<link rel="stylesheet" href="../_static/pydoctheme_dark.css" media="(prefers-color-scheme: dark)" id="pydoctheme_dark_css">61    <link rel="shortcut icon" type="image/png" href="../_static/py.svg">62            <script type="text/javascript" src="../_static/copybutton.js"></script>63            <script type="text/javascript" src="../_static/menu.js"></script>64            <script type="text/javascript" src="../_static/search-focus.js"></script>65            <script type="text/javascript" src="../_static/themetoggle.js"></script> 66            <script type="text/javascript" src="../_static/rtd_switcher.js"></script>67            <meta name="readthedocs-addons-api-version" content="1">68 69  </head>70<body>71<div class="mobile-nav">72    <input type="checkbox" id="menuToggler" class="toggler__input" aria-controls="navigation"73           aria-pressed="false" aria-expanded="false" role="button" aria-label="Menu">74    <nav class="nav-content" role="navigation">75        <label for="menuToggler" class="toggler__label">76            <span></span>77        </label>78        <span class="nav-items-wrapper">79            <a href="https://www.python.org/" class="nav-logo">80                <img src="../_static/py.svg" alt="Python logo">81            </a>82            <span class="version_switcher_placeholder"></span>83            <form role="search" class="search" action="../search.html" method="get">84                <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" class="search-icon">85                    <path fill-rule="nonzero" fill="currentColor" d="M15.5 14h-.79l-.28-.27a6.5 6.5 0 001.48-5.34c-.47-2.78-2.79-5-5.59-5.34a6.505 6.505 0 00-7.27 7.27c.34 2.8 2.56 5.12 5.34 5.59a6.5 6.5 0 005.34-1.48l.27.28v.79l4.25 4.25c.41.41 1.08.41 1.49 0 .41-.41.41-1.08 0-1.49L15.5 14zm-6 0C7.01 14 5 11.99 5 9.5S7.01 5 9.5 5 14 7.01 14 9.5 11.99 14 9.5 14z"></path>86                </svg>87                <input placeholder="Quick search" aria-label="Quick search" type="search" name="q">88                <input type="submit" value="Go">89            </form>90        </span>91    </nav>92    <div class="menu-wrapper">93        <nav class="menu" role="navigation" aria-label="main navigation">94            <div class="language_switcher_placeholder"></div>95            96<label class="theme-selector-label">97    Theme98    <select class="theme-selector" oninput="activateTheme(this.value)">99        <option value="auto" selected>Auto</option>100        <option value="light">Light</option>101        <option value="dark">Dark</option>102    </select>103</label>104  <div>105    <h4>Previous topic</h4>106    <p class="topless"><a href="xdrlib.html"107                          title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xdrlib</span></code> — Encode and decode XDR data</a></p>108  </div>109  <div>110    <h4>Next topic</h4>111    <p class="topless"><a href="../extending/index.html"112                          title="next chapter">Extending and Embedding the Python Interpreter</a></p>113  </div>114  <script>115    document.addEventListener('DOMContentLoaded', () => {116        const title = document.querySelector('meta[property="og:title"]').content;117        const elements = document.querySelectorAll('.improvepage');118        const pageurl = window.location.href.split('?')[0];119        elements.forEach(element => {120            const url = new URL(element.href.split('?')[0].replace("-nojs", ""));121            url.searchParams.set('pagetitle', title);122            url.searchParams.set('pageurl', pageurl);123            url.searchParams.set('pagesource', "library/security_warnings.rst");124            element.href = url.toString();125        });126    });127  </script>128  <div role="note" aria-label="source link">129    <h3>This page</h3>130    <ul class="this-page-menu">131      <li><a href="../bugs.html">Report a bug</a></li>132      <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>133      <li>134        <a href="https://github.com/python/cpython/blob/main/Doc/library/security_warnings.rst?plain=1"135            rel="nofollow">Show source136        </a>137      </li>138      139    </ul>140  </div>141        </nav>142    </div>143</div>144 145  146    <div class="related" role="navigation" aria-label="Related">147      <h3>Navigation</h3>148      <ul>149        <li class="right" style="margin-right: 10px">150          <a href="../genindex.html" title="General Index"151             accesskey="I">index</a></li>152        <li class="right" >153          <a href="../py-modindex.html" title="Python Module Index"154             >modules</a> |</li>155        <li class="right" >156          <a href="../extending/index.html" title="Extending and Embedding the Python Interpreter"157             accesskey="N">next</a> |</li>158        <li class="right" >159          <a href="xdrlib.html" title="xdrlib — Encode and decode XDR data"160             accesskey="P">previous</a> |</li>161 162          <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>163          <li><a href="https://www.python.org/">Python</a> &#187;</li>164          <li class="switchers">165            <div class="language_switcher_placeholder"></div>166            <div class="version_switcher_placeholder"></div>167          </li>168          <li>169              170          </li>171    <li id="cpython-language-and-version">172      <a href="../index.html">3.15.0a6 Documentation</a> &#187;173    </li>174 175          <li class="nav-item nav-item-1"><a href="index.html" accesskey="U">The Python Standard Library</a> &#187;</li>176        <li class="nav-item nav-item-this"><a href="">Security Considerations</a></li>177                <li class="right">178                    179 180    <div class="inline-search" role="search">181        <form class="inline-search" action="../search.html" method="get">182          <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">183          <input type="submit" value="Go">184        </form>185    </div>186                     |187                </li>188            <li class="right">189<label class="theme-selector-label">190    Theme191    <select class="theme-selector" oninput="activateTheme(this.value)">192        <option value="auto" selected>Auto</option>193        <option value="light">Light</option>194        <option value="dark">Dark</option>195    </select>196</label> |</li>197            198      </ul>199    </div>    200 201    <div class="document">202      <div class="documentwrapper">203        <div class="bodywrapper">204          <div class="body" role="main">205            206  <section id="security-considerations">207<span id="index-0"></span><span id="security-warnings"></span><h1>Security Considerations<a class="headerlink" href="#security-considerations" title="Link to this heading">¶</a></h1>208<p>The following modules have specific security considerations:</p>209<ul class="simple">210<li><p><a class="reference internal" href="base64.html#module-base64" title="base64: RFC 4648: Base16, Base32, Base64 Data Encodings; Base85 and Ascii85"><code class="xref py py-mod docutils literal notranslate"><span class="pre">base64</span></code></a>: <a class="reference internal" href="base64.html#base64-security"><span class="std std-ref">base64 security considerations</span></a> in211<span class="target" id="index-1"></span><a class="rfc reference external" href="https://datatracker.ietf.org/doc/html/rfc4648.html"><strong>RFC 4648</strong></a></p></li>212<li><p><a class="reference internal" href="hashlib.html#module-hashlib" title="hashlib: Secure hash and message digest algorithms."><code class="xref py py-mod docutils literal notranslate"><span class="pre">hashlib</span></code></a>: <a class="reference internal" href="hashlib.html#hashlib-usedforsecurity"><span class="std std-ref">all constructors take a “usedforsecurity” keyword-only213argument disabling known insecure and blocked algorithms</span></a></p></li>214<li><p><a class="reference internal" href="http.server.html#module-http.server" title="http.server: HTTP server and request handlers."><code class="xref py py-mod docutils literal notranslate"><span class="pre">http.server</span></code></a> is not suitable for production use, only implementing215basic security checks. See the <a class="reference internal" href="http.server.html#http-server-security"><span class="std std-ref">security considerations</span></a>.</p></li>216<li><p><a class="reference internal" href="logging.html#module-logging" title="logging: Flexible event logging system for applications."><code class="xref py py-mod docutils literal notranslate"><span class="pre">logging</span></code></a>: <a class="reference internal" href="logging.config.html#logging-eval-security"><span class="std std-ref">Logging configuration uses eval()</span></a></p></li>217<li><p><a class="reference internal" href="multiprocessing.html#module-multiprocessing" title="multiprocessing: Process-based parallelism."><code class="xref py py-mod docutils literal notranslate"><span class="pre">multiprocessing</span></code></a>: <a class="reference internal" href="multiprocessing.html#multiprocessing-recv-pickle-security"><span class="std std-ref">Connection.recv() uses pickle</span></a></p></li>218<li><p><a class="reference internal" href="pickle.html#module-pickle" title="pickle: Convert Python objects to streams of bytes and back."><code class="xref py py-mod docutils literal notranslate"><span class="pre">pickle</span></code></a>: <a class="reference internal" href="pickle.html#pickle-restrict"><span class="std std-ref">Restricting globals in pickle</span></a></p></li>219<li><p><a class="reference internal" href="random.html#module-random" title="random: Generate pseudo-random numbers with various common distributions."><code class="xref py py-mod docutils literal notranslate"><span class="pre">random</span></code></a> shouldn’t be used for security purposes, use <a class="reference internal" href="secrets.html#module-secrets" title="secrets: Generate secure random numbers for managing secrets."><code class="xref py py-mod docutils literal notranslate"><span class="pre">secrets</span></code></a>220instead</p></li>221<li><p><a class="reference internal" href="shelve.html#module-shelve" title="shelve: Python object persistence."><code class="xref py py-mod docutils literal notranslate"><span class="pre">shelve</span></code></a>: <a class="reference internal" href="shelve.html#shelve-security"><span class="std std-ref">shelve is based on pickle and thus unsuitable for222dealing with untrusted sources</span></a></p></li>223<li><p><a class="reference internal" href="ssl.html#module-ssl" title="ssl: TLS/SSL wrapper for socket objects"><code class="xref py py-mod docutils literal notranslate"><span class="pre">ssl</span></code></a>: <a class="reference internal" href="ssl.html#ssl-security"><span class="std std-ref">SSL/TLS security considerations</span></a></p></li>224<li><p><a class="reference internal" href="subprocess.html#module-subprocess" title="subprocess: Subprocess management."><code class="xref py py-mod docutils literal notranslate"><span class="pre">subprocess</span></code></a>: <a class="reference internal" href="subprocess.html#subprocess-security"><span class="std std-ref">Subprocess security considerations</span></a></p></li>225<li><p><a class="reference internal" href="tempfile.html#module-tempfile" title="tempfile: Generate temporary files and directories."><code class="xref py py-mod docutils literal notranslate"><span class="pre">tempfile</span></code></a>: <a class="reference internal" href="tempfile.html#tempfile-mktemp-deprecated"><span class="std std-ref">mktemp is deprecated due to vulnerability to race226conditions</span></a></p></li>227<li><p><a class="reference internal" href="xml.html#module-xml" title="xml: Package containing XML processing modules"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml</span></code></a>: <a class="reference internal" href="xml.html#xml-security"><span class="std std-ref">XML security</span></a></p></li>228<li><p><a class="reference internal" href="zipfile.html#module-zipfile" title="zipfile: Read and write ZIP-format archive files."><code class="xref py py-mod docutils literal notranslate"><span class="pre">zipfile</span></code></a>: <a class="reference internal" href="zipfile.html#zipfile-resources-limitations"><span class="std std-ref">maliciously prepared .zip files can cause disk volume229exhaustion</span></a></p></li>230</ul>231<p>The <a class="reference internal" href="../using/cmdline.html#cmdoption-I"><code class="xref std std-option docutils literal notranslate"><span class="pre">-I</span></code></a> command line option can be used to run Python in isolated232mode. When it cannot be used, the <a class="reference internal" href="../using/cmdline.html#cmdoption-P"><code class="xref std std-option docutils literal notranslate"><span class="pre">-P</span></code></a> option or the233<span class="target" id="index-2"></span><a class="reference internal" href="../using/cmdline.html#envvar-PYTHONSAFEPATH"><code class="xref std std-envvar docutils literal notranslate"><span class="pre">PYTHONSAFEPATH</span></code></a> environment variable can be used to not prepend a234potentially unsafe path to <a class="reference internal" href="sys.html#sys.path" title="sys.path"><code class="xref py py-data docutils literal notranslate"><span class="pre">sys.path</span></code></a> such as the current directory, the235script’s directory or an empty string.</p>236</section>237 238 239            <div class="clearer"></div>240          </div>241        </div>242      </div>243      <div class="sphinxsidebar" role="navigation" aria-label="Main">244        <div class="sphinxsidebarwrapper">245  <div>246    <h4>Previous topic</h4>247    <p class="topless"><a href="xdrlib.html"248                          title="previous chapter"><code class="xref py py-mod docutils literal notranslate"><span class="pre">xdrlib</span></code> — Encode and decode XDR data</a></p>249  </div>250  <div>251    <h4>Next topic</h4>252    <p class="topless"><a href="../extending/index.html"253                          title="next chapter">Extending and Embedding the Python Interpreter</a></p>254  </div>255  <script>256    document.addEventListener('DOMContentLoaded', () => {257        const title = document.querySelector('meta[property="og:title"]').content;258        const elements = document.querySelectorAll('.improvepage');259        const pageurl = window.location.href.split('?')[0];260        elements.forEach(element => {261            const url = new URL(element.href.split('?')[0].replace("-nojs", ""));262            url.searchParams.set('pagetitle', title);263            url.searchParams.set('pageurl', pageurl);264            url.searchParams.set('pagesource', "library/security_warnings.rst");265            element.href = url.toString();266        });267    });268  </script>269  <div role="note" aria-label="source link">270    <h3>This page</h3>271    <ul class="this-page-menu">272      <li><a href="../bugs.html">Report a bug</a></li>273      <li><a class="improvepage" href="../improve-page-nojs.html">Improve this page</a></li>274      <li>275        <a href="https://github.com/python/cpython/blob/main/Doc/library/security_warnings.rst?plain=1"276            rel="nofollow">Show source277        </a>278      </li>279      280    </ul>281  </div>282        </div>283<div id="sidebarbutton" title="Collapse sidebar">284<span>«</span>285</div>286 287      </div>288      <div class="clearer"></div>289    </div>  290    <div class="related" role="navigation" aria-label="Related">291      <h3>Navigation</h3>292      <ul>293        <li class="right" style="margin-right: 10px">294          <a href="../genindex.html" title="General Index"295             >index</a></li>296        <li class="right" >297          <a href="../py-modindex.html" title="Python Module Index"298             >modules</a> |</li>299        <li class="right" >300          <a href="../extending/index.html" title="Extending and Embedding the Python Interpreter"301             >next</a> |</li>302        <li class="right" >303          <a href="xdrlib.html" title="xdrlib — Encode and decode XDR data"304             >previous</a> |</li>305 306          <li><img src="../_static/py.svg" alt="Python logo" style="vertical-align: middle; margin-top: -1px"></li>307          <li><a href="https://www.python.org/">Python</a> &#187;</li>308          <li class="switchers">309            <div class="language_switcher_placeholder"></div>310            <div class="version_switcher_placeholder"></div>311          </li>312          <li>313              314          </li>315    <li id="cpython-language-and-version">316      <a href="../index.html">3.15.0a6 Documentation</a> &#187;317    </li>318 319          <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> &#187;</li>320        <li class="nav-item nav-item-this"><a href="">Security Considerations</a></li>321                <li class="right">322                    323 324    <div class="inline-search" role="search">325        <form class="inline-search" action="../search.html" method="get">326          <input placeholder="Quick search" aria-label="Quick search" type="search" name="q" id="search-box">327          <input type="submit" value="Go">328        </form>329    </div>330                     |331                </li>332            <li class="right">333<label class="theme-selector-label">334    Theme335    <select class="theme-selector" oninput="activateTheme(this.value)">336        <option value="auto" selected>Auto</option>337        <option value="light">Light</option>338        <option value="dark">Dark</option>339    </select>340</label> |</li>341            342      </ul>343    </div>  344    <div class="footer">345    &copy; <a href="../copyright.html">Copyright</a> 2001 Python Software Foundation.346    <br>347    This page is licensed under the Python Software Foundation License Version 2.348    <br>349    Examples, recipes, and other code in the documentation are additionally licensed under the Zero Clause BSD License.350    <br>351    352      See <a href="/license.html">History and License</a> for more information.<br>353    354    355    <br>356 357    The Python Software Foundation is a non-profit corporation.358<a href="https://www.python.org/psf/donations/">Please donate.</a>359<br>360    <br>361      Last updated on Mar 10, 2026 (08:58 UTC).362    363      <a href="/bugs.html">Found a bug</a>?364    365    <br>366 367    Created using <a href="https://www.sphinx-doc.org/">Sphinx</a> 8.2.3.368    </div>369 370  </body>371</html>