HTTP Client Library Vulnerability in Python's urllib3 by Python Software Foundation
CVE-2026-97687

7.6HIGH

Key Information:

Vendor

Urllib3

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-97687?

The vulnerability in urllib3 affects HTTPS proxy connections due to improper handling of TLS settings. Specified configurations like proxy_ssl_context and cert_reqs may allow an attacker to manipulate connections, leading to unauthorized access and potential data compromise. When using an HTTPS proxy, these TLS settings should be independently verified to prevent situations where a malicious actor can intercept traffic or impersonate a legitimate proxy. This flaw has been addressed in version 2.8.0 of urllib3.

Affected Version(s)

urllib3 >= 1.26.0, < 2.8.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.