HTTP Client Library Vulnerability in Python's urllib3 by Python Software Foundation
CVE-2026-97687
7.6HIGH
What is CVE-2026-97687?
The vulnerability in urllib3 affects HTTPS proxy connections due to improper handling of TLS settings. Specified configurations like proxy_ssl_context and cert_reqs may allow an attacker to manipulate connections, leading to unauthorized access and potential data compromise. When using an HTTPS proxy, these TLS settings should be independently verified to prevent situations where a malicious actor can intercept traffic or impersonate a legitimate proxy. This flaw has been addressed in version 2.8.0 of urllib3.
Affected Version(s)
urllib3 >= 1.26.0, < 2.8.0
