🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Security
Fixed the following security issues:
- The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
HTTPResponse.stream()andread_chunked()could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)- Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)
Important
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.
Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.
Note
CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.
Deprecations & Removals
- Deprecated using an empty collection as the
Retryoptionallowed_methodsto retry any verb. (#5044)
Features
- Added
Url.auth_decodedandUrl.auth_decoded_joinedconvenience properties to the result ofparse_url(). (#4945) - Added
basic_auth_encodingandproxy_basic_auth_encodingparameters tourllib3.util.make_headers(). (#5092)
Bugfixes
-
Fixed response header handling to replace obsolete folded header lines (
obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such asSet-Cookie. (#1362) -
Fixed usage of
proxy_ssl_contextwithProxyManagerwhenuse_forwarding_for_https=True. Passingssl_contextinstead ofproxy_ssl_contextfor HTTPS proxies in this configuration now emits aFutureWarningand will raise an error in v3.0. (#2577) -
Changed behavior of the default
ConnectionPool.poolinitialization.LifoQueueis now resolved from thequeuemodule after theConnectionPoolis instantiated instead of using the default cachedQueueClsclass property. This is done because sometimes thequeue.LifoQueueis monkey-patched late in the program, such as by gevent. (#3289) -
Raised
UnrewindableBodyErrorinstead ofValueErrorwhen retrying a request whose body hadtell()but notseek(). (#3779) -
Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)
-
Fixed
HTTPResponse.drain_conn()to discard unread response data in 64 KiB chunks (same as the defaultamtwhen doingHTTPResponse.stream(...)). (#5019) -
Fixed
is_ipaddress()to detect non-standard IPv4 forms accepted bysocket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029) -
Fixed
HTTPConnectionPool.urlopenraising a misleadingFullPoolErrorinstead ofValueErrorwhen called with an invalidtimeoutargument on a pool created withblock=True. (#5059) -
Fixed port-zero handling to preserve explicit
:0values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration,connection_from_url(), and HTTP/2 request authority. (#5071, #5101) -
Fixed a bug where
PoolManagerpassed theassert_hostnameandassert_fingerprintparameters to HTTP connection pools. (#5077) -
Fixed
HTTPConnectionPool.urlopen()and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079) -
Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)
-
Fixed
HTTPSConnection.connect()overridingProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.HTTPSConnectionno longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use itsssl_contextas a fallback when an HTTPS proxy forwards an HTTP target. (#5093) -
Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)
-
Fixed an
AttributeErroron Python built with OpenSSL 4+, wheressl.PROTOCOL_TLSv1no longer exists. (#5097) -
Fixed
urllib3.contrib.pyopensslto use cryptography APIs when reading a certificate subject and loading encrypted private keys, avoidingDeprecationWarningraised by pyOpenSSL 26.3.0+. (#5103) -
Fixed handling of HTTP 303 redirects for requests with chunked or file-like bodies. (#5161)
-
Fixed
assert_fingerprint()to raiseSSLErrorinstead ofbinascii.Errorwhen a fingerprint has a supported length but contains non-hexadecimal characters. (#5211)
Misc
- Added a
testdependency group containing the minimum dependencies needed to run the test suite, intended for downstream packagers. Thedev-baseandmypygroups now include this new group viainclude-group, removing duplication. (#3594) - Fixed test failures with pytest >= 9.1. (#5094)
- Enabled JSPI tests with Firefox in the Emscripten test suite. (#5166)
- Improved streamed response decoding performance. (#5209)
- Fixed flaky tests. (#5232, #5234, #5239)