angler-fishThe Vulnerability History Project

Fixed #19987 -- Disabled host validation when DEBUG=True.

      The documentation promises that host validation is disabled when
DEBUG=True, that all hostnames are accepted. Domains not compliant with
RFC 1034/1035 were however being validated, this validation has now been
removed when DEBUG=True.

Additionally, when DEBUG=False a more detailed SuspiciousOperation
exception message is provided when host validation fails because the
hostname is not RFC 1034/1035 compliant.
    
commit 1c3c21b38d154eff0286c194711dced2ac39dd3d
+2 -7
-16
expand_less