From 897999de04bdeea77a1f32b7d195ad9b1a0a5392 Mon Sep 17 00:00:00 2001 From: Rupayon Haldar <80724680+rupayon123@users.noreply.github.com> Date: Thu, 1 Oct 2026 05:24:58 -0400 Subject: [PATCH 1/2] gh-158500: Reject trailing date characters --- Lib/_pydatetime.py | 6 ++++++ Lib/test/datetimetester.py | 2 ++ .../Library/2026-10-01-04-30-00.gh-issue-158500.a1b2c3.rst | 2 ++ Modules/_datetimemodule.c | 7 +++++++ 4 files changed, 17 insertions(+) create mode 100644 Misc/NEWS.d/next/Library/2026-10-01-04-30-00.gh-issue-158500.a1b2c3.rst diff --git a/Lib/_pydatetime.py b/Lib/_pydatetime.py index 50126d039e830a2..68f6f5b76de6f95 100644 --- a/Lib/_pydatetime.py +++ b/Lib/_pydatetime.py @@ -389,6 +389,9 @@ def _parse_isoformat_date(dtstr): pos += has_sep dayno = _read_isoformat_component(dtstr[pos:pos + 1], 1) + pos += 1 + if pos != len(dtstr): + raise ValueError("Invalid isoformat string") return list(_isoweek_to_gregorian(year, weekno, dayno)) else: @@ -399,6 +402,9 @@ def _parse_isoformat_date(dtstr): pos += has_sep day = _read_isoformat_component(dtstr[pos:pos + 2], 2) + pos += 2 + if pos != len(dtstr): + raise ValueError("Invalid isoformat string") return [year, month, day] diff --git a/Lib/test/datetimetester.py b/Lib/test/datetimetester.py index 716c662ad453f4a..bbd9e4f47db1f9a 100644 --- a/Lib/test/datetimetester.py +++ b/Lib/test/datetimetester.py @@ -2114,6 +2114,8 @@ def test_fromisoformat_fails(self): '2020-W 5', # space in the week number '2020061', # 7 chars: day slice reads a 1-character tail '2020-W2', # 1-digit week number + '2020010112', # Trailing characters after a basic-format date + '2020W011xx', # Trailing characters after a basic-format week date '٢025-03-09', # Unicode characters '2009\ud80002\ud80028', # Separators are surrogate codepoints ] diff --git a/Misc/NEWS.d/next/Library/2026-10-01-04-30-00.gh-issue-158500.a1b2c3.rst b/Misc/NEWS.d/next/Library/2026-10-01-04-30-00.gh-issue-158500.a1b2c3.rst new file mode 100644 index 000000000000000..cbf103e699124b5 --- /dev/null +++ b/Misc/NEWS.d/next/Library/2026-10-01-04-30-00.gh-issue-158500.a1b2c3.rst @@ -0,0 +1,2 @@ +Fix :meth:`datetime.date.fromisoformat` accepting basic-format date strings +with trailing characters. diff --git a/Modules/_datetimemodule.c b/Modules/_datetimemodule.c index bd76b3bd81cce40..9a78a27f462cf36 100644 --- a/Modules/_datetimemodule.c +++ b/Modules/_datetimemodule.c @@ -991,6 +991,10 @@ parse_isoformat_date(const char *dtstr, const size_t len, int *year, int *month, iso_day = 1; } + if ((size_t)(p - dtstr) != len) { + return -1; + } + int rv = iso_to_ymd(*year, iso_week, iso_day, year, month, day); if (rv) { return -3 + rv; @@ -1011,6 +1015,9 @@ parse_isoformat_date(const char *dtstr, const size_t len, int *year, int *month, if (p == NULL) { return -1; } + if ((size_t)(p - dtstr) != len) { + return -1; + } return 0; } From 57801f4600f1fd890874bc2e852e81fe9851e4cb Mon Sep 17 00:00:00 2001 From: Rupayon Haldar <80724680+rupayon123@users.noreply.github.com> Date: Thu, 1 Oct 2026 08:18:26 -0400 Subject: [PATCH 2/2] gh-158500: Cover multibyte trailing date data --- Lib/test/datetimetester.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/Lib/test/datetimetester.py b/Lib/test/datetimetester.py index bbd9e4f47db1f9a..d76a1f7a4a6e38f 100644 --- a/Lib/test/datetimetester.py +++ b/Lib/test/datetimetester.py @@ -2119,6 +2119,9 @@ def test_fromisoformat_fails(self): '٢025-03-09', # Unicode characters '2009\ud80002\ud80028', # Separators are surrogate codepoints ] + if not issubclass(self.theclass, datetime): + # 9 characters, 10 UTF-8 bytes; exercise the C parser's 10-byte path. + bad_strs.append('20200101\u00e9') for bad_str in bad_strs: with self.assertRaises(ValueError):