[pkg-vuln] CVE-2026-97687 in urllib3@2.7.0 #913

Open
opened 2026-10-01 06:01:53 +00:00 by kert · 0 comments
Owner

Severity: HIGH
Package: urllib3 @ 2.7.0
Fixed in: 2.8.0

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TL

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-97687

**Severity:** HIGH **Package:** `urllib3` @ `2.7.0` **Fixed in:** `2.8.0` urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TL **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-97687
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-10-01 06:01:53 +00:00
kert added the qualityci labels 2026-10-01 06:01:53 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#913