Skip to content

Update dependency urllib3 to v2.8.0 [SECURITY] (main) - #1330

Merged
williamlin-suse merged 1 commit into
mainfrom
renovate/main-urllib3
Oct 1, 2026
Merged

williamlin-suse merged 1 commit into
mainfrom
renovate/main-urllib3

Conversation

@renovate-rancher

@renovate-rancher renovate-rancher Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
urllib3 (changelog) ==2.7.0 → ==2.8.0 age confidence

urllib3: HTTPS proxy TLS configuration may be ignored or overridden

CVE-2026-97687 / GHSA-8988-9cw3-xx77

More information

Details

Impact

urllib3 supports configuring TLS independently for an HTTPS proxy and the target server.

proxy_ssl_context, proxy_assert_hostname, and proxy_assert_fingerprint configure the TLS connection to the proxy. ssl_context and the other target-specific TLS parameters configure the connection to the target server.

In urllib3 versions 1.26.0 through 2.7.0, these configurations were not consistently separated. Depending on the proxy mode, urllib3 could:

  1. Ignore proxy_ssl_context and use the target server's SSL context for the TLS connection to an HTTPS forwarding proxy.
  2. Override the HTTPS proxy's certificate-verification policy with the target server's certificate-verification policy.
  3. Apply target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials to the TLS connection to an HTTPS forwarding proxy.

In particular, configuring cert_reqs="CERT_NONE" for a target server could overwrite the verify_mode of the SSL context configured for the HTTPS proxy. This modification occurred in place and persisted on the context object, potentially disabling proxy certificate verification for later connections that reused the same context.

An attacker able to intercept the connection to an HTTPS proxy may be able to impersonate the proxy when the effective proxy TLS configuration disables certificate verification or otherwise accepts the attacker's certificate. This may occur, for example, when the target server's trust or identity policy is incorrectly applied to the proxy connection.

When HTTPS forwarding is enabled, an impersonated proxy can observe or modify forwarded requests and responses, potentially exposing credentials, authentication tokens, request bodies, response data, and other sensitive information.

A TLS client certificate intended for the target server may also be presented to the proxy or to an attacker impersonating it. This can disclose the client's identity and provide proof of possession of the corresponding private key. The private key itself is not transmitted during the TLS handshake.

In CONNECT tunneling mode, impersonating the HTTPS proxy does not by itself defeat the separate end-to-end TLS connection between the client and the target server.

Affected Usages

Code using urllib3 versions 1.26.0 through 2.7.0 may be affected in any of the following cases.

1. The target SSL context is used for an HTTPS forwarding proxy

HTTPS requests are forwarded through an HTTPS proxy with use_forwarding_for_https=True, and proxy_ssl_context is configured for the proxy.

urllib3 may ignore proxy_ssl_context and use the target server's ssl_context for the proxy TLS handshake. The proxy may therefore be verified using the target server's trust and certificate policy instead of the policy explicitly configured for the proxy.

2. The target verification policy overrides the proxy policy

An HTTPS proxy is configured with proxy_ssl_context, while the target server uses a different certificate-verification policy.

urllib3 may apply the target server's cert_reqs value to the proxy SSL context. For example, setting cert_reqs="CERT_NONE" for the target server may also disable certificate verification for the HTTPS proxy, even when proxy_ssl_context was configured to require verification.

This issue can affect the TLS connection to an HTTPS proxy in both forwarding and CONNECT tunneling configurations.

3. A mutated proxy SSL context is reused

The same SSL context is reused as proxy_ssl_context across multiple connections, and certificate verification is disabled for one target server.

urllib3 may modify the proxy SSL context's verify_mode in place. Later connections that reuse the same context may therefore connect to the HTTPS proxy without certificate verification.

4. Target-specific TLS identity or credentials are applied to the proxy

HTTPS requests are forwarded through an HTTPS proxy with use_forwarding_for_https=True, and target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials are configured.

urllib3 may apply these target-specific settings to the proxy TLS handshake. This may cause urllib3 to:

  • send SNI intended for the target server to the proxy;
  • verify the proxy using a hostname or certificate fingerprint intended for the target server; or
  • present a TLS client certificate intended for the target server to the proxy.

Code connecting through a plain HTTP proxy does not establish a TLS connection to the proxy and is not affected by this issue.

Remediation

Upgrade to urllib3 2.8.0 or later.

urllib3 2.8.0 independently applies the explicitly configured proxy_ssl_context and proxy-specific certificate assertions to the HTTPS proxy connection. Target-specific SNI, certificate assertions, and TLS client certificate parameters are no longer applied to the HTTPS proxy handshake.

For backward compatibility, when an HTTPS proxy is used with use_forwarding_for_https=True and proxy_ssl_context is not provided, urllib3 2.8.0 continues to use ssl_context for the TLS connection to the proxy. This configuration emits a FutureWarning. In urllib3 3.0, passing ssl_context with use_forwarding_for_https=True for an HTTPS proxy will raise an error. Applications should use proxy_ssl_context to configure TLS for an HTTPS forwarding proxy.

The fixes were implemented in commits b6447295fff7b38fdffc67e0df9712d60cef3cc3 and 07408cec79d1856d81bb42c74a904a24fdb9e465.

Severity

  • CVSS Score: 7.6 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

CVE-2026-97689 / GHSA-vxq7-64xx-v4gw

More information

Details

Impact

urllib3's streaming API is designed for efficiently handling large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When decoding a chunked-transfer-encoded response, this API reads each chunk's size field by buffering until it sees \n or EOF.

A malicious HTTP server can return Transfer-Encoding: chunked and then send a very long run of bytes without any newline, causing the streaming client to buffer that entire run before urllib3 can reject the chunk size as invalid and allocate more memory than intended.

To fix the issue, we'll reject chunk-size fields larger than 65536 bytes, as already done in the non-streaming case, which is currently handled by the Python standard library. Note that this only applies to reading the chunk-size field, not the chunk data, which is already handled correctly. Thus, there shouldn't be any impact for non-malicious servers.

Affected usages

Applications and libraries using urllib3 versions earlier than 2.8.0 may be affected when streaming a chunked response from untrusted sources. Specifically, this affects the read_chunked() and stream() methods of the HTTPResponse object.

This also affects requests streaming API, which uses urllib3 under the hood.

Remediation

Upgrade to urllib3 version 2.8.0 or later, where chunk-size fields larger than 65536 will be rejected. If upgrading is not immediately possible, consider reading the response at once using the read() method.

Severity

  • CVSS Score: 8.9 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


urllib3: Chunked Deflate streaming can enter an infinite loop

CVE-2026-97688 / GHSA-gh4c-6fx4-qh6g

More information

Details

Impact

urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading content in chunks instead of loading the entire response body into memory at once.

urllib3 can decompress response bodies according to the HTTP Content-Encoding header. When streaming a compressed, chunked response, urllib3 first consumes data already buffered by the decoder before reading the next HTTP chunk.

However, urllib3 versions from 2.6.2 through 2.7.0 could enter an infinite loop when a chunked response contained bytes after the end of the Deflate stream. If the decompressed body exceeded the requested streaming chunk size, Python's zlib implementation could retain the trailing bytes as unconsumed input after reaching the end of the compressed stream. urllib3 would repeatedly attempt to decode those same bytes without making progress or reading more data from the network.

A malicious server could exploit this behavior to cause excessive CPU usage and prevent the affected request from completing on the client. Network read timeouts would not interrupt the loop because no further socket operation was required.

Affected usages

Applications and libraries using urllib3 versions 2.6.2 through 2.7.0 may be affected when all of the following conditions are met:

  1. Compressed responses from an untrusted source are streamed using HTTPResponse.stream(amt=N) or HTTPResponse.read_chunked(amt=N) with a positive, finite chunk size.
  2. Content decoding is enabled.
  3. The response uses both Transfer-Encoding: chunked and Content-Encoding: deflate.
  4. The decoded body exceeds the requested chunk size and the encoded body contains bytes after the end of the Deflate stream.

HTTPResponse.stream() uses a finite chunk size by default and is therefore affected when the other conditions are met.

Remediation

Upgrade to urllib3 2.8.0, in which the Deflate decoder stops accepting input after reaching the end of the compressed stream and no longer reports trailing bytes as data that can produce more decoded output.

If upgrading is not immediately possible, disable automatic content decoding for responses from untrusted sources by setting decode_content=False, or reject streamed responses using the Deflate content encoding. Applications that disable automatic decoding must handle the compressed response safely at another layer.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


urllib3: HTTPS proxy TLS configuration may be ignored or overridden

CVE-2026-97687 / GHSA-8988-9cw3-xx77

More information

Details

Impact

urllib3 supports configuring TLS independently for an HTTPS proxy and the target server.

proxy_ssl_context, proxy_assert_hostname, and proxy_assert_fingerprint configure the TLS connection to the proxy. ssl_context and the other target-specific TLS parameters configure the connection to the target server.

In urllib3 versions 1.26.0 through 2.7.0, these configurations were not consistently separated. Depending on the proxy mode, urllib3 could:

  1. Ignore proxy_ssl_context and use the target server's SSL context for the TLS connection to an HTTPS forwarding proxy.
  2. Override the HTTPS proxy's certificate-verification policy with the target server's certificate-verification policy.
  3. Apply target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials to the TLS connection to an HTTPS forwarding proxy.

In particular, configuring cert_reqs="CERT_NONE" for a target server could overwrite the verify_mode of the SSL context configured for the HTTPS proxy. This modification occurred in place and persisted on the context object, potentially disabling proxy certificate verification for later connections that reused the same context.

An attacker able to intercept the connection to an HTTPS proxy may be able to impersonate the proxy when the effective proxy TLS configuration disables certificate verification or otherwise accepts the attacker's certificate. This may occur, for example, when the target server's trust or identity policy is incorrectly applied to the proxy connection.

When HTTPS forwarding is enabled, an impersonated proxy can observe or modify forwarded requests and responses, potentially exposing credentials, authentication tokens, request bodies, response data, and other sensitive information.

A TLS client certificate intended for the target server may also be presented to the proxy or to an attacker impersonating it. This can disclose the client's identity and provide proof of possession of the corresponding private key. The private key itself is not transmitted during the TLS handshake.

In CONNECT tunneling mode, impersonating the HTTPS proxy does not by itself defeat the separate end-to-end TLS connection between the client and the target server.

Affected Usages

Code using urllib3 versions 1.26.0 through 2.7.0 may be affected in any of the following cases.

1. The target SSL context is used for an HTTPS forwarding proxy

HTTPS requests are forwarded through an HTTPS proxy with use_forwarding_for_https=True, and proxy_ssl_context is configured for the proxy.

urllib3 may ignore proxy_ssl_context and use the target server's ssl_context for the proxy TLS handshake. The proxy may therefore be verified using the target server's trust and certificate policy instead of the policy explicitly configured for the proxy.

2. The target verification policy overrides the proxy policy

An HTTPS proxy is configured with proxy_ssl_context, while the target server uses a different certificate-verification policy.

urllib3 may apply the target server's cert_reqs value to the proxy SSL context. For example, setting cert_reqs="CERT_NONE" for the target server may also disable certificate verification for the HTTPS proxy, even when proxy_ssl_context was configured to require verification.

This issue can affect the TLS connection to an HTTPS proxy in both forwarding and CONNECT tunneling configurations.

3. A mutated proxy SSL context is reused

The same SSL context is reused as proxy_ssl_context across multiple connections, and certificate verification is disabled for one target server.

urllib3 may modify the proxy SSL context's verify_mode in place. Later connections that reuse the same context may therefore connect to the HTTPS proxy without certificate verification.

4. Target-specific TLS identity or credentials are applied to the proxy

HTTPS requests are forwarded through an HTTPS proxy with use_forwarding_for_https=True, and target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials are configured.

urllib3 may apply these target-specific settings to the proxy TLS handshake. This may cause urllib3 to:

  • send SNI intended for the target server to the proxy;
  • verify the proxy using a hostname or certificate fingerprint intended for the target server; or
  • present a TLS client certificate intended for the target server to the proxy.

Code connecting through a plain HTTP proxy does not establish a TLS connection to the proxy and is not affected by this issue.

Remediation

Upgrade to urllib3 2.8.0 or later.

urllib3 2.8.0 independently applies the explicitly configured proxy_ssl_context and proxy-specific certificate assertions to the HTTPS proxy connection. Target-specific SNI, certificate assertions, and TLS client certificate parameters are no longer applied to the HTTPS proxy handshake.

For backward compatibility, when an HTTPS proxy is used with use_forwarding_for_https=True and proxy_ssl_context is not provided, urllib3 2.8.0 continues to use ssl_context for the TLS connection to the proxy. This configuration emits a FutureWarning. In urllib3 3.0, passing ssl_context with use_forwarding_for_https=True for an HTTPS proxy will raise an error. Applications should use proxy_ssl_context to configure TLS for an HTTPS forwarding proxy.

The fixes were implemented in commits b6447295fff7b38fdffc67e0df9712d60cef3cc3 and 07408cec79d1856d81bb42c74a904a24fdb9e465.

Severity

  • CVSS Score: 7.6 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


urllib3: Chunked Deflate streaming can enter an infinite loop

CVE-2026-97688 / GHSA-gh4c-6fx4-qh6g

More information

Details

Impact

urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading content in chunks instead of loading the entire response body into memory at once.

urllib3 can decompress response bodies according to the HTTP Content-Encoding header. When streaming a compressed, chunked response, urllib3 first consumes data already buffered by the decoder before reading the next HTTP chunk.

However, urllib3 versions from 2.6.2 through 2.7.0 could enter an infinite loop when a chunked response contained bytes after the end of the Deflate stream. If the decompressed body exceeded the requested streaming chunk size, Python's zlib implementation could retain the trailing bytes as unconsumed input after reaching the end of the compressed stream. urllib3 would repeatedly attempt to decode those same bytes without making progress or reading more data from the network.

A malicious server could exploit this behavior to cause excessive CPU usage and prevent the affected request from completing on the client. Network read timeouts would not interrupt the loop because no further socket operation was required.

Affected usages

Applications and libraries using urllib3 versions 2.6.2 through 2.7.0 may be affected when all of the following conditions are met:

  1. Compressed responses from an untrusted source are streamed using HTTPResponse.stream(amt=N) or HTTPResponse.read_chunked(amt=N) with a positive, finite chunk size.
  2. Content decoding is enabled.
  3. The response uses both Transfer-Encoding: chunked and Content-Encoding: deflate.
  4. The decoded body exceeds the requested chunk size and the encoded body contains bytes after the end of the Deflate stream.

HTTPResponse.stream() uses a finite chunk size by default and is therefore affected when the other conditions are met.

Remediation

Upgrade to urllib3 2.8.0, in which the Deflate decoder stops accepting input after reaching the end of the compressed stream and no longer reports trailing bytes as data that can produce more decoded output.

If upgrading is not immediately possible, disable automatic content decoding for responses from untrusted sources by setting decode_content=False, or reject streamed responses using the Deflate content encoding. Applications that disable automatic decoding must handle the compressed response safely at another layer.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

CVE-2026-97689 / GHSA-vxq7-64xx-v4gw

More information

Details

Impact

urllib3's streaming API is designed for efficiently handling large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When decoding a chunked-transfer-encoded response, this API reads each chunk's size field by buffering until it sees \n or EOF.

A malicious HTTP server can return Transfer-Encoding: chunked and then send a very long run of bytes without any newline, causing the streaming client to buffer that entire run before urllib3 can reject the chunk size as invalid and allocate more memory than intended.

To fix the issue, we'll reject chunk-size fields larger than 65536 bytes, as already done in the non-streaming case, which is currently handled by the Python standard library. Note that this only applies to reading the chunk-size field, not the chunk data, which is already handled correctly. Thus, there shouldn't be any impact for non-malicious servers.

Affected usages

Applications and libraries using urllib3 versions earlier than 2.8.0 may be affected when streaming a chunked response from untrusted sources. Specifically, this affects the read_chunked() and stream() methods of the HTTPResponse object.

This also affects requests streaming API, which uses urllib3 under the hood.

Remediation

Upgrade to urllib3 version 2.8.0 or later, where chunk-size fields larger than 65536 will be rejected. If upgrading is not immediately possible, consider reading the response at once using the read() method.

Severity

  • CVSS Score: 8.9 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

urllib3/urllib3 (urllib3)

v2.8.0

Compare Source

==================

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden.
    (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size
    line of unbounded length in memory. (High severity,
    GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity,
    GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in
``proxy_ssl_context``, and proxy identity checks with
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option
    allowed_methods to retry any verb.
    (#&#8203;5044 <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience
    properties to the result of parse_url().
    (#&#8203;4945 <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to
    urllib3.util.make_headers().
    (#&#8203;5092 <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines
    (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF
    sequences from appearing in header values such as Set-Cookie.
    (#&#8203;1362 <https://github.com/urllib3/urllib3/issues/1362>__)

  • Fixed usage of proxy_ssl_context with ProxyManager when
    use_forwarding_for_https=True. Passing ssl_context instead of
    proxy_ssl_context for HTTPS proxies in this configuration now emits a
    FutureWarning and will raise an error in v3.0.
    (#&#8203;2577 <https://github.com/urllib3/urllib3/issues/2577>__)

  • Changed behavior of the default ConnectionPool.pool initialization.
    LifoQueue is now resolved from the queue module after the
    ConnectionPool is instantiated instead of using the default cached
    QueueCls class property. This is done because sometimes the
    queue.LifoQueue is monkey-patched late in the program, such as by gevent.
    (#&#8203;3289 <https://github.com/urllib3/urllib3/issues/3289>__)

  • Raised UnrewindableBodyError instead of ValueError when retrying a
    request whose body had tell() but not seek().
    (#&#8203;3779 <https://github.com/urllib3/urllib3/issues/3779>__)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with
    the proxy server.
    (#&#8203;3785 <https://github.com/urllib3/urllib3/issues/3785>__)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB
    chunks (same as the default amt when doing HTTPResponse.stream(...)).
    (#&#8203;5019 <https://github.com/urllib3/urllib3/issues/5019>__)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by
    socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and
    decimal integers (2130706433), ensuring SSL certificate verification uses
    the correct mode for these addresses.
    (#&#8203;5029 <https://github.com/urllib3/urllib3/issues/5029>__)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError
    instead of ValueError when called with an invalid timeout argument on
    a pool created with block=True.
    (#&#8203;5059 <https://github.com/urllib3/urllib3/issues/5059>__)

  • Fixed port-zero handling to preserve explicit :0 values instead of
    substituting the default ports 80 or 443 in URL parsing, pool selection,
    proxy configuration, connection_from_url(), and HTTP/2 request authority.
    (#&#8203;5071 <https://github.com/urllib3/urllib3/issues/5071>,
    #&#8203;5101 <https://github.com/urllib3/urllib3/issues/5101>
    )

  • Fixed a bug where PoolManager passed the assert_hostname and
    assert_fingerprint parameters to HTTP connection pools.
    (#&#8203;5077 <https://github.com/urllib3/urllib3/issues/5077>__)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL
    fragments from absolute request targets before sending requests.
    (#&#8203;5079 <https://github.com/urllib3/urllib3/issues/5079>__)

  • Added safeguards to the proxy tunneling code to prevent potential security
    issues when handling invalid characters in the proxy host and HTTP headers.
    This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
    the standard library does not contain the fix; those on newer Python versions
    should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
    (#&#8203;5091 <https://github.com/urllib3/urllib3/issues/5091>__)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's
    certificate policy and proxy identity checks with the target connection's TLS
    settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client
    credentials to forwarding proxy handshakes and continues to use its
    ssl_context as a fallback when an HTTPS proxy forwards an HTTP target.
    (#&#8203;5093 <https://github.com/urllib3/urllib3/issues/5093>__)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
    invalid host input such as raw spaces and control characters, malformed
    percent-encodings, and percent-encoded control characters in HTTP(S) hosts
    and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
    normalization now also follows RFC 3986 normalization rules for
    percent-encoded octets by decoding percent-encoded unreserved characters and
    uppercasing the hexadecimal digits of retained percent-encoded octets.
    (#&#8203;5095 <https://github.com/urllib3/urllib3/issues/5095>__)

  • Fixed an AttributeError on Python built with OpenSSL 4+, where
    ssl.PROTOCOL_TLSv1 no longer exists.
    (#&#8203;5097 <https://github.com/urllib3/urllib3/issues/5097>__)

  • Fixed urllib3.contrib.pyopenssl to use cryptography APIs when reading a
    certificate subject and loading encrypted private keys, avoiding
    DeprecationWarning raised by pyOpenSSL 26.3.0+.
    (#&#8203;5103 <https://github.com/urllib3/urllib3/issues/5103>__)

  • Fixed handling of HTTP 303 redirects for requests with chunked or file-like
    bodies.
    (#&#8203;5161 <https://github.com/urllib3/urllib3/issues/5161>__)

  • Fixed assert_fingerprint() to raise SSLError instead of
    binascii.Error when a fingerprint has a supported length but contains
    non-hexadecimal characters.
    (#&#8203;5211 <https://github.com/urllib3/urllib3/issues/5211>__)

Misc

  • Added a test dependency group containing the minimum dependencies needed
    to run the test suite, intended for downstream packagers. The dev-base
    and mypy groups now include this new group via include-group,
    removing duplication.
    (#&#8203;3594 <https://github.com/urllib3/urllib3/issues/3594>__)
  • Fixed test failures with pytest >= 9.1.
    (#&#8203;5094 <https://github.com/urllib3/urllib3/issues/5094>__)
  • Enabled JSPI tests with Firefox in the Emscripten test suite.
    (#&#8203;5166 <https://github.com/urllib3/urllib3/issues/5166>__)
  • Improved streamed response decoding performance.
    (#&#8203;5209 <https://github.com/urllib3/urllib3/issues/5209>__)
  • Fixed flaky tests.
    (#&#8203;5232 <https://github.com/urllib3/urllib3/issues/5232>,
    #&#8203;5234 <https://github.com/urllib3/urllib3/issues/5234>
    ,
    #&#8203;5239 <https://github.com/urllib3/urllib3/issues/5239>__)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@renovate-rancher
renovate-rancher Bot requested a review from a team as a code owner October 1, 2026 04:46
@williamlin-suse
williamlin-suse merged commit a136def into main Oct 1, 2026
4 checks passed
@renovate-rancher
renovate-rancher Bot deleted the renovate/main-urllib3 branch October 2, 2026 04:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant