From d78d5b52fa1b3cd449c3bec313a7a5b065c38e4b Mon Sep 17 00:00:00 2001 From: Mira Weller Date: Tue, 8 Sep 2026 15:00:35 +0200 Subject: [PATCH] Prevent parsing non-standard-compliant JSON float values (Z#23245937 / PRT-021) --- src/pretix/helpers/monkeypatching.py | 9 +++++++ src/tests/helpers/test_json.py | 39 ++++++++++++++++++++++++++++ 2 files changed, 48 insertions(+) create mode 100644 src/tests/helpers/test_json.py diff --git a/src/pretix/helpers/monkeypatching.py b/src/pretix/helpers/monkeypatching.py index 83a231e554..8447e3f710 100644 --- a/src/pretix/helpers/monkeypatching.py +++ b/src/pretix/helpers/monkeypatching.py @@ -251,6 +251,13 @@ def monkeypatch_csrf_middleware(): BaseCsrfMiddleware._set_csrf_cookie = CsrfViewMiddleware._set_csrf_cookie +def monkeypatch_json_constants(): + from json.decoder import _CONSTANTS # noqa + del _CONSTANTS['-Infinity'] + del _CONSTANTS['Infinity'] + del _CONSTANTS['NaN'] + + def monkeypatch_all_at_ready(): monkeypatch_vobject_performance() monkeypatch_pillow_safer() @@ -259,3 +266,5 @@ def monkeypatch_all_at_ready(): monkeypatch_cookie_morsel() monkeypatch_reportlab_imagereader() monkeypatch_csrf_middleware() + monkeypatch_json_constants() + diff --git a/src/tests/helpers/test_json.py b/src/tests/helpers/test_json.py new file mode 100644 index 0000000000..6027142f6e --- /dev/null +++ b/src/tests/helpers/test_json.py @@ -0,0 +1,39 @@ +# +# This file is part of pretix (Community Edition). +# +# Copyright (C) 2014-2020 Raphael Michel and contributors +# Copyright (C) 2020-today pretix GmbH and contributors +# +# This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General +# Public License as published by the Free Software Foundation in version 3 of the License. +# +# ADDITIONAL TERMS APPLY: Pursuant to Section 7 of the GNU Affero General Public License, additional terms are +# applicable granting you additional permissions and placing additional restrictions on your usage of this software. +# Please refer to the pretix LICENSE file to obtain the full terms applicable to this work. If you did not receive +# this file, see . +# +# This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more +# details. +# +# You should have received a copy of the GNU Affero General Public License along with this program. If not, see +# . +# +import json + +import pytest + + +def test_allowed_json(): + assert json.loads('{"float":1.5,"int":161,"arr":[]}') == {"float": 1.5, "int": 161, "arr": []} + + +def test_disallowed_json_float_consts(): + with pytest.raises(KeyError): + json.loads("Infinity") + with pytest.raises(KeyError): + json.loads("-Infinity") + with pytest.raises(KeyError): + json.loads("NaN") + with pytest.raises(KeyError): + json.loads("[123, NaN, Infinity, -Infinity]")