Original report at: https://github.com/cherrypy/cherrypy/issues/1974 Reading it, I'm not sure if upstream considers it a real security issue or not. Nevertheless, 18.8.0 adds some filtering (with "We can expand that list of characters if needed") and I suppose we can stabilize it just in case.
cleanup done.
Thanks, all done!