Skip to content

Scheduled monthly dependency update for October - #767

Open
pyup-bot wants to merge 5 commits into
masterfrom
pyup-scheduled-update-2026-10-01
Open

pyup-bot wants to merge 5 commits into
masterfrom
pyup-scheduled-update-2026-10-01

Conversation

@pyup-bot

@pyup-bot pyup-bot commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Update fonttools from 4.61.0 to 4.66.1.

Changelog

4.66.1

----------------------------

- [designspaceLib] When splitting a DesignSpace v5 document with ``makeNames=True``
(as ``varLib.build_many`` does), family and style names set explicitly on an
instance now take precedence over the ones computed from the STAT labels, in
all languages, and a PostScript name is no longer made up from the labels for
an instance that has its own style name (3131, 4206, 4208).
- [cmap] Decompiling a format 4 subtable whose ``idRangeOffset`` points outside
``glyphIndexArray`` now raises ``TTLibError``. A negative index used to silently
map the code point to the wrong glyph, and one past the end raised a bare
``AssertionError`` (4209).
- [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte
row is 32768 or higher, which failed with ``struct.error`` (4210).

4.66.0

----------------------------

- Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later.
``fontTools.misc.enumTools`` now only re-exports ``enum.StrEnum`` and is
deprecated. Explicitly test and declare support for Python 3.15 (4183, 4196).
- [unicodedata] Update the bundled script, script extension, block and
bidi-mirroring tables to Unicode 18.0.0, and require ``unicodedata2`` 18.0.0
when it is used (4192, 4197).
- [feaLib] Support ``language`` statements listing multiple language tags, e.g.
``language AZE CRT;``, as Glyphs does and as proposed for the spec
(adobe-type-tools/feature_file_workshops8): the following rules and lookup
references are registered under every listed language. ``dflt`` cannot be
combined with other tags. ``LanguageStatement.language`` is still the first
tag; all of them are in the new ``languages`` attribute (4201, 4202).
- [feaLib] Fix lookups being dropped when a ``script``/``language`` pair is
repeated within a feature block: the repeated statement replaced the language
system's lookups with a fresh copy of the default ones (4189).
- [feaLib] Raise ``FeatureLibError`` instead of ``UnboundLocalError`` when a
``STAT`` table block lacks ``ElidedFallbackName`` or ``ElidedFallbackNameID``
(3834, 4179).
- [cffLib] Always recompile the CFF2 ``VarStore`` when saving. Previously the
bytes compiled by an earlier save were reused, so a CFF2 variable font that
was saved and then modified in place, e.g. by the instancer, was written with
a stale ``VarStore`` next to its updated charstrings (4199).
- [ttLib] Support static ``VARC`` fonts that omit ``fvar`` while retaining
``gvar`` or CFF2 variation data for component-internal axes: hidden axes are
addressed by index and ``gvar`` can compile, decompile and round-trip through
TTX without ``fvar``, reading the axis count from a new ``axisCount``
element (4187, 4188).
- [ttLib] Fix drawing ``VARC`` components whose condition is negated
(format 5), which raised ``AttributeError`` (4191).
- [instancer] Fix ``VARC`` axis references left stale when removing an
unrelated axis, reject pinning or restricting axes referenced by ``VARC``
components, and stop culling avar2 ranges for component-internal variations,
which can reach outside the font-level ranges (4190, 4193).
- [bezierTools] Preserve exact endpoints in ``splitQuadraticAtT`` and
``splitCubicAtTC`` as well, like ``splitCubicAtT`` since 4.55.4
(3742, 4194).
- [bezierTools] Fix ``ZeroDivisionError`` in ``lineLineIntersections`` for
collinear vertical lines; they are now treated as parallel like horizontal
ones (3515, 4181).
- [subset] ``pyftsubset`` now preserves the input font's flavor (WOFF, WOFF2)
when ``--flavor`` is omitted, instead of writing uncompressed sfnt data under
the same extension; pass ``--flavor=none`` to force uncompressed output
(3630, 4182).
- [merge] Report incompatible ``unitsPerEm`` values by name, with the input
values, instead of a bare assertion (2844, 4184).
- [designspaceLib] Fix the type annotation and documentation of
``DesignSpaceDocument.default``, which holds a ``SourceDescriptor``, not a
source name (2994, 4186).
- [ttLib.sfnt] Raise ``TTLibError`` instead of ``AssertionError`` for
inconsistent WOFF table, metadata and private-data lengths, so the checks
also hold under ``python -O`` (4178).
- [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well:
lxml's ``resolve_entities="internal"`` still fetched external parameter
entities before lxml 6.1.3, so a crafted DTD could read local files into
parsed XML content (4195).
- [cmap] Bound the expansion of format 4 segments and format 12/13 groups when
decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or
overlapping groups are skipped with a warning, and groups mapped to the
missing glyph are not expanded. A crafted font could previously exhaust
memory with a single group ending at 0xFFFFFFFF (4204).
- [varLib.avar] Escape axis names and tags when ``varLib.avar.unbuild`` emits
its designspace snippet, so a crafted font cannot inject markup (4203).

4.65.0

----------------------------

- [glyf] Add ``__iter__``, ``items`` and ``values`` methods to the ``glyf`` table
to make it more dict-like (4156).
- [feaLib] Escape the anonymous block tag when scanning for its terminator, so tags
containing regex metacharacters are matched literally (4167).
- [varLib] Strip directory components from ``<variable-font name="..."/>`` when
deriving the output filename in the ``varLib`` command line, so a designspace
cannot write outside the output directory (4168).
- [feaLib] Fix tracking of the current script and language across redundant
``script`` statements. Rules following a ``script`` statement that names the
first declared language system no longer end up under the ``DFLT`` script, and
a ``script`` statement naming the already-current script still narrows the
language systems and terminates the current lookup while leaving the
``lookupflag`` alone, matching makeotf (1824, 2522, 4169).
- [varLib.interpolatable] Escape glyph names in the HTML report (4172).
- [otlLib] Fix overflow handling when building contextual lookups: offset overflows
now raise ``OTLOffsetOverflowError`` instead of ``AttributeError`` so another
contextual format can be tried (regression from 3439). When all formats
overflow, split the ruleset in halves until it fits (4171).

4.64.0

----------------------------

- [feaLib] Fix name-table parsing for multibyte Mac encodings (1196, 4092).
- [ttProgram] Also indent TrueType assembly following ``IDEF[ ]``, like function
definitions (4093).
- [subset] Keep East Asian spacing ``palt`` by default (4094).
- [subset] Bug fix for MATH table in which constructions for glyphs that are only
added during MATH closure were kept (4096).
- [ufoLib] Make glyph-to-group construction accessible outside of lookup function
(4102).
- [glyf] Use reverse glyph map for O(1) ``__setitem__`` membership (4103).
- [ttLib] Fix ``fixLookupOverFlows()`` reporting success when it had not promoted
any lookup to Extension, masking unresolvable overflows.
- [ttLib] Add support for TrueType Collection version 2 (4100).
- [ttLib] Pin a single head.modified timestamp across ``TTCollection.save`` (4111).
- [ttLib] Give an actionable error when LookupList overflow is unrecoverable (4109).
- [ttLib] Add support for the AAT bitmap tables ``bhed``, ``bdat``, ``bloc``,
variants of ``head``, ``EBDT``, ``EBLC`` used in legacy Apple bitmap-only fonts
(4115).
- [ttLib] Check ``OS/2`` fsSelection/macStyle consistency against ``bhed`` as well
as ``head`` (4118, 4119).
- [misc.roundTools] Add types and documentation (4123).
- [varLib.instancer] Instance the ``BASE`` table (4137).
- [varLib.instancer] Fix Private-dict ``vsindex`` handling in ``instantiateCFF2``
(4129, 4132).
- [varLib.instancer] Fix crash instancing CFF2 fonts without a VariationStore
(4130, 4131).
- [sfnt] Raise ``TTLibError`` instead of ``AssertionError`` or ``struct.error``
when reading a font truncated within the table directory or a table entry
(4147, 4149).
- [misc.xmlWriter] Escape the ``]]>`` terminator inside CDATA sections, so an SVG
document containing it can no longer smuggle markup past a TTX round trip
(4139).
- [varLib.instancer] Implement avar2 partial-instancing: the avar version 2
ItemVariationStore is adjusted so that remaining axes behave the same after
limiting the designspace (4045).
- [feaLib] Add shorthand for the value at the default location in a variable
scalar: ``(100 wght=900:120)`` means ``(wght=400:100 wght=900:120)`` when the
wght default is 400 (4024).
- [cmap] Raise ``TTLibError`` for a truncated or out-of-bounds cmap subtable
header (4151).
- [designspaceLib] Reject conflicting duplicate inputs in axis maps instead of
silently keeping the last one (4153).
- [designspaceLib] Read an empty ``<lib>`` element as an empty lib instead of
raising ``IndexError`` (4142, 4144).
- [colorLib] Raise a legible error when a COLRv0 layer, or a COLRv1 PaintGlyph or
PaintColrGlyph, references a glyph missing from the glyphMap, instead of failing
obscurely later (2629, 4141).
- [cmap] Don't drop subtables in unsupported formats when compiling or dumping a
font read from binary (4136).
- [ttLib] Implement ``splitSinglePos`` so GPOS lookup type 1 offset overflows can
be recovered by splitting the subtable (4091, 4108).
- [cmap] Round-trip empty Macintosh format 2 subtables (3663, 4117).
- [glyf] Raise ``TTLibError`` instead of ``RecursionError`` when ``recalcBounds()``
hits a composite-component reference cycle (3899, 4116).
- [svgLib] Fix crash parsing an SVG path with consecutive closepath commands
(``Z Z``) (4122).
- [ttLib] Fix ``DefaultTable`` type annotations (4126).
- [ttLib] Add support for the ``EBSC`` (Embedded Bitmap Scaling) table (4113).
- [svgLib] Suppress spurious close segments caused by floating-point drift in
relative path commands (3860, 4127).
- [qu2cu] Fix ``TypeError`` in the Cython-compiled build when ``Qu2CuPen`` passes
tuple splines (4160).
- [mort] Add semantic decompilation, TTX, and compilation support for
rearrangement, contextual-substitution, ligature, and insertion subtables
(4158, 4159, 4161).
- [svgLib] Start a new subpath at the just-closed subpath's initial point when a
drawto command follows a closepath, per SVG spec (4154, 4155).
- [misc.filesystem] **SECURITY** Reject paths that resolve outside the filesystem
root: a malicious UFO could read arbitrary files via ``..`` components in
``contents.plist``, and a crafted ``.ufoz`` could create files outside its
temporary mirror (4124).
- [ttLib] **SECURITY** Sanitise glyph names used as filenames in EBDT/CBDT
``ttx -z extfile`` export, preventing arbitrary file writes from untrusted
fonts (4128).
- [misc.etree] **SECURITY** Don't resolve external XML entities in ``XMLParser``
when lxml is used, preventing XXE file disclosure on lxml < 5.0 (4145).
- [subset] Fully prune ``VARC`` auxiliary data: collect and remap variation
indices referenced by condition tables when subsetting the ``MultiVarStore``,
and drop the ``AxisIndicesList``, ``ConditionList``, and ``MultiVarStore``
when they end up empty (4162).

4.63.0

----------------------------

- [ttLib] Add support for Apple Color Emoji ``bgcl`` table (4065).
- [ttLib] Add support for ``IFT`` and ``IFTX`` tables (Incremental Font Transfer,
PatchMapFormat2) (4070, 4072).
- [otData] Introduce ``FieldSpec`` dataclass for OpenType table schema definitions,
replacing raw tuples in ``otData.py`` (4076).
- [Feat] Show ``name`` table strings as comments next to label IDs in TTX output,
matching the convention used by ``fvar``, ``STAT``, ``trak`` (4089).
- [cu2qu] Fix Cython complex-division rounding difference in
``split_cubic_into_three`` that could cause ±1 off-curve coordinate shifts
(3928, 4083).
- [designspaceLib] Fix ``map_backward`` for many-to-one (flat-segment) axis maps
that silently dropped entries via dict comprehension
(googlefonts/ufo2ft978, 4085).
- [OS/2] Fix ``setUnicodeRanges`` to accept reserved bits 123-127, restoring
round-trip with ``getUnicodeRanges`` and fixing ``recalcUnicodeRanges`` crash
in the subsetter (4087, 4088).
- [cython] Declare Cython extensions as free-threading compatible on Python 3.13+,
so that importing them on free-threaded Python no longer re-enables the GIL
(4073, 4090).

4.62.1

----------------------------

- [feaLib] Extend contextual rule merging to all rule types: single subst, GSUB/GPOS
named lookups, ignore rules, and chained alternate subst (4061).

4.62.0

----------------------------

- [diff] Add new ``fonttools diff`` command for comparing font files, imported from the
``fdiff`` project and heavily reworked (1190, 4007, 4009, 4011, 4013, 4019).
- [feaLib] Fix ``VariableScalar`` interpolation bug with non-linear avar mappings. Also
decouple ``VariableScalar`` from compiled fonts, allowing it to work with designspace data
before compilation (3938, 4054).
- [feaLib] Fix ``VariableScalar`` axis ordering and iterative delta rounding to match fontc
behavior (4053).
- [feaLib] Merge chained multi subst rules with same context into a single subtable instead of
emitting one subtable per glyph (4016, 4058).
- [feaLib] Pass location to ``ConditionsetStatement`` to fix glyphsLib round-tripping
(fontra/fontra-glyphs130, 4057).
- [feaLib] Write ``0xFFFF`` instead of ``0`` for missing nameIDs in ``cv`` feature params
(4010, 4012).
- [cmap] Fix ``CmapSubtable.__lt__()`` ``TypeError`` on Python 3 when subtables share the
same encoding record, and add compile-time validation for unique encoding records (4035,
4055).
- [svgLib] Skip non-element XML nodes (comments, processing instructions) when drawing SVG
paths (4042, 4043).
- [glifLib] Fix regression reading glyph outlines when ``glyphObject=None`` (4030, 4031).
- [pointPen] Fix ``SegmentToPointPen`` edge case: only remove a duplicate final point on
``closePath()`` if it is an on-curve point (4014, 4015).
- [cffLib] **SECURITY** Replace ``eval()`` with ``safeEval()`` in ``parseBlendList()`` to
prevent arbitrary code execution from crafted TTX files (4039, 4040).
- [ttLib] Remove defunct Adobe SING Glyphlet tables (``META``, ``SING``, ``GMAP``, ``GPKG``)
(4044).
- [varLib.interpolatable] Various bugfixes: fix swapped nodeTypes assignment, duplicate
kink-detector condition, typos, CFF2 vsindex parsing, glyph existence check, and plot
helpers (4046).
- [varLib.models] Fix ``getSubModel`` not forwarding ``extrapolate``/``axisRanges``; check
location uniqueness after stripping zeros (4047).
- [varLib] Fix ``--variable-fonts`` filter in ``build_many``; remove dead code and fix
comments (4048).
- [avar] Preserve existing name table in build; keep ``unbuild`` return types consistent;
validate ``map`` CLI coordinates (4051).
- [cu2qu/qu2cu] Add input validation: reject non-positive tolerances, validate curve inputs
and list lengths (4052).
- [colorLib] Raise a clear ``ColorLibError`` when base glyphs are missing from glyphMap,
instead of a confusing ``KeyError`` (4041).
- [glyf] Remove unnecessary ``fvar`` table dependency (4017).
- [fvar/trak] Remove unnecessary ``name`` table dependency (4018).
- [ufoLib] Relax guideline validation to follow the updated spec (3537, 3553).
- [ttFont] Fix ``saveXML`` regression with empty table lists, clarify docstring (4025, 4026,
4056).
- [setup.py] Link ``libm`` for Cython extensions using math functions (4028, 4029).
- Add typing annotations for ``DSIG``, ``DefaultTable``, ``ttProgram`` (4033).

4.61.1

----------------------------

- [otlLib] buildCoverage: return empty Coverage instead of None (4003, 4004).
- [instancer] bug fix in ``avar2`` full instancing (4002).
- [designspaceLib] Preserve empty conditionsets when serializing to XML (4001).
- [fontBu ilder] Fix FontBuilder ``setupOS2()`` default params globally polluted (3996, 3997).
- [ttFont] Add more typing annotations to ttFont, xmlWriter, sfnt, varLib.models and others (3952, 3826).
- Explicitly test and declare support for Python 3.14, even though we were already shipping pre-built wheels for it (3990).
Links

Update idna from 3.11 to 3.20.

Changelog

3.20

- Update to Unicode 18.0.0.
- Better enforcement of the domain length limit in the incremental
codec.
- Add support for Python 3.15.

3.19

- Restore the `std3_rules` option, which had no effect since changes
to UTS 46 processing in Unicode 16. Note that `uts46_remap()`
defaults to enabling STD3 rules, so direct callers will see input
containing non-LDH ASCII characters rejected again.
- Performance improvements to UTS 46 mapping, particularly for
ASCII-only domains.
- Test on free-threaded CPython with the GIL disabled and document
thread safety.
- Expose the Unicode version of the generated tables as
`idna.unicode_version`, and show it in `idna --version`.
- Add `code`, `text`, `codepoint` and `position` attributes to
`IDNAError` so that the failed rule and the offending character can
be identified without parsing the exception message.
- The deprecated `transitional` argument to `encode()` and
`uts46_remap()` is now completely ignored, and gives a deprecation warning
for the latter.
- Reject A-labels that are not the canonical Punycode encoding of
their U-label.
- Fix CONTEXTJ violations raising `IDNAError` instead of
`InvalidCodepointContext`.
- Consistently raise `IDNAError` for empty labels and non-ASCII bytes
passed to label helper functions and the incremental codec.
- Add property-based tests, extended fuzzing targets, coverage
measurement, and CI checks that the data tables match the generator
output.
- Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.

3.18

- When decoding a domain, add a `display` argument that will pass
through invalid labels rather than raising an exception.

3.17

- Substantial 75% reduction in memory usage through new data
structures and some optimization in processing speed.
- Added a general 1024-character input length cap to the public
validation, conversion, and codec entry points. This is well above
any legitimate domain or label and guards against pathological
inputs.

3.16

- Add a command-line interface (`python -m idna`, also available as
the `idna` script). Encodes or decodes one or more domains supplied
as arguments or on standard input, with options to select A-label
or U-label output and control error handling.
- Raise the minimum supported Python version to 3.9
- Various code quality improvements

3.15

- Enforce DNS-length cap on individual labels early in `check_label`,
short-circuiting contextual-rule processing for oversized input
while staying compatible with UTS 46 usage.
- Tidy core helpers: hoist bidi category sets to module-level
frozensets (avoiding per-codepoint list construction), simplify
length checks, and reuse the shared `_unicode_dots_re` from
`idna.core` in the codec module.
- Use `raise ... from err` for proper exception chaining and
switch internal string formatting to f-strings.
- Allow `flit_core` 4.x in the build backend.
- Expand the ruff lint set (flake8-bugbear, flake8-simplify,
pyupgrade, perflint) and apply the surfaced fixes; pin lint CI
to Python 3.14.
- Add Dependabot configuration for GitHub Actions.
- Convert README and HISTORY from reStructuredText to Markdown.
- Reference CVE-2026-45409 for the 3.14 advisory in place of the
initial GHSA identifier.

Thanks to Felix Yan, Stan Ulbrych, and metsw24-max for
contributions to this release.

3.14

- Removed opportunity to process long inputs into quadratic
time by rejecting oversize inputs up-front. Closes a bypass
of the CVE-2024-3651 mitigation. [CVE-2026-45409]

Thanks to Stan Ulbrych for reporting the issue.

3.13

- Correct classification error for codepoint U+A7F1

3.12

- Update to Unicode 17.0.0.
- Issue a deprecation warning for the transitional argument.
- Added lazy-loading to provide some performance improvements.
- Removed vestiges of code related to Python 2 support, including
segmentation of data structures specific to Jython.

Thanks to Rodrigo Nogueira for contributions to this release.
Links

Update pillow from 12.1.1 to 12.3.0.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update requests from 2.32.5 to 2.34.2.

Changelog

2.34.2

-------------------
- Moved `headers` input type back to `Mapping` to avoid invariance issues
with `MutableMapping` and inferred dict types. Users calling
`Request.headers.update()` may need to narrow typing in their code. (7441)

2.34.1

-------------------

**Bugfixes**
- Widened `json` input type from `dict` and `list` to `Mapping`
and `Sequence`. (7436)
- Changed `headers` input type to MutableMapping and removed `None` from
`Request.headers` typing to improve handling for users. (7431)
- `Response.reason` moved from `str | None` to `str` to improve handling
for users. (7437)
- Fixed a bug where some bodies with custom `__getattr__` implementations
weren't being properly detected as Iterables. (7433)

2.34.0

-------------------

**Announcements**
- Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy, pyright,
and ty. We believe types are comprehensive but if you find issues, please
report them to the pinned tracking issue.

Special thanks to bastimeyer, cthoyt, edgarrmondragon, and srittau for
helping review and test the types ahead of the release. (7272)

**Improvements**
- Digest Auth hashing algorithms have added `usedforsecurity=False` to clarify
security considerations. (7310)
- Requests added support for Python 3.15 based on beta1. Downstream projects
should be able to start testing prior to its release in October. (7422)
- Requests added support for Python 3.14t. (7419)

**Bugfixes**
- ``Response.history`` no longer contains a reference to itself, preventing
accidental looping when traversing the history list. (7328)
- Requests no longer performs greedy matching on no_proxy domains. The
proxy_bypass implementation has been updated with CPython's fix from
bpo-39057. (7427)
- Requests no longer incorrectly strips duplicate leading slashes in
URI paths. This should address user issues with specific presigned
URLs. Note the full fix requires urllib3 2.7.0+. (7315)

2.33.1

-------------------

**Bugfixes**
- Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary
files in the tmp directory. (7305)
- Fixed Content-Type header parsing for malformed values. (7309)
- Improved error consistency for malformed header values. (7308)

2.33.0

-------------------

**Announcements**
- 📣 Requests is adding inline types. If you have a typed code base that
uses Requests, please take a look at 7271. Give it a try, and report
any gaps or feedback you may have in the issue. 📣

**Security**
- CVE-2026-25645 ``requests.utils.extract_zipped_paths`` now extracts
contents to a non-deterministic location to prevent malicious file
replacement. This does not affect default usage of Requests, only
applications calling the utility function directly.

**Improvements**
- Migrated to a PEP 517 build system using setuptools. (7012)

**Bugfixes**
- Fixed an issue where an empty netrc entry could cause
malformed authentication to be applied to Requests on
Python 3.11+. (7205)

**Deprecations**
- Dropped support for Python 3.9 following its end of support. (7196)

**Documentation**
- Various typo fixes and doc improvements.
Links

Update urllib3 from 2.6.3 to 2.8.0.

Changelog

2.8.0

==================

Security
--------

Fixed the following security issues:

- The TLS configuration for HTTPS proxies could be ignored or overridden.
(High severity, `GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`__)
- ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a chunk-size
line of unbounded length in memory. (High severity,
`GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`__)
- Chunked Deflate streaming could enter an infinite loop. (Medium severity,
`GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`__)

.. caution::

 urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
 overridden by destination settings. Configurations relying on that
 behavior may require changes.

 Configure proxy CA certificates and client certificates in
 ``proxy_ssl_context``, and proxy identity checks with
 ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
 Destination client certificates and identity overrides no longer
 apply to HTTPS forwarding proxy connections.


Deprecations & Removals
-----------------------

- Deprecated using an empty collection as the ``Retry`` option
``allowed_methods`` to retry any verb.
(`5044 <https://github.com/urllib3/urllib3/issues/5044>`__)


Features
--------

- Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined`` convenience
properties to the result of ``parse_url()``.
(`4945 <https://github.com/urllib3/urllib3/issues/4945>`__)
- Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding`` parameters to
``urllib3.util.make_headers()``.
(`5092 <https://github.com/urllib3/urllib3/issues/5092>`__)


Bugfixes
--------

- Fixed response header handling to replace obsolete folded header lines
(`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF
sequences from appearing in header values such as ``Set-Cookie``.
(`1362 <https://github.com/urllib3/urllib3/issues/1362>`__)
- Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when
``use_forwarding_for_https=True``. Passing ``ssl_context`` instead of
``proxy_ssl_context`` for HTTPS proxies in this configuration now emits a
``FutureWarning`` and will raise an error in v3.0.
(`2577 <https://github.com/urllib3/urllib3/issues/2577>`__)
- Changed behavior of the default ``ConnectionPool.pool`` initialization.
``LifoQueue`` is now resolved from the ``queue`` module after the
``ConnectionPool`` is instantiated instead of using the default cached
``QueueCls`` class property. This is done because sometimes the
``queue.LifoQueue`` is monkey-patched late in the program, such as by gevent.
(`3289 <https://github.com/urllib3/urllib3/issues/3289>`__)
- Raised ``UnrewindableBodyError`` instead of ``ValueError`` when retrying a
request whose body had ``tell()`` but not ``seek()``.
(`3779 <https://github.com/urllib3/urllib3/issues/3779>`__)
- Decoded percent-encoded SOCKS proxy credentials before authenticating with
the proxy server.
(`3785 <https://github.com/urllib3/urllib3/issues/3785>`__)
- Fixed ``HTTPResponse.drain_conn()`` to discard unread response data in 64 KiB
chunks (same as the default ``amt`` when doing ``HTTPResponse.stream(...)``).
(`5019 <https://github.com/urllib3/urllib3/issues/5019>`__)
- Fixed ``is_ipaddress()`` to detect non-standard IPv4 forms accepted by
``socket.connect``, such as hex (``0x7f000001``), octal (``0177.0.0.1``), and
decimal integers (``2130706433``), ensuring SSL certificate verification uses
the correct mode for these addresses.
(`5029 <https://github.com/urllib3/urllib3/issues/5029>`__)
- Fixed ``HTTPConnectionPool.urlopen`` raising a misleading ``FullPoolError``
instead of ``ValueError`` when called with an invalid ``timeout`` argument on
a pool created with ``block=True``.
(`5059 <https://github.com/urllib3/urllib3/issues/5059>`__)
- Fixed port-zero handling to preserve explicit ``:0`` values instead of
substituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration, ``connection_from_url()``, and HTTP/2 request authority.
(`5071 <https://github.com/urllib3/urllib3/issues/5071>`__,
`5101 <https://github.com/urllib3/urllib3/issues/5101>`__)
- Fixed a bug where ``PoolManager`` passed the ``assert_hostname`` and
``assert_fingerprint`` parameters to HTTP connection pools.
(`5077 <https://github.com/urllib3/urllib3/issues/5077>`__)
- Fixed ``HTTPConnectionPool.urlopen()`` and HTTP proxy forwarding to strip URL
fragments from absolute request targets before sending requests.
(`5079 <https://github.com/urllib3/urllib3/issues/5079>`__)
- Added safeguards to the proxy tunneling code to prevent potential security
issues when handling invalid characters in the proxy host and HTTP headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
the standard library does not contain the fix; those on newer Python versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(`5091 <https://github.com/urllib3/urllib3/issues/5091>`__)
- Fixed ``HTTPSConnection.connect()`` overriding ``ProxyConfig.ssl_context``'s
certificate policy and proxy identity checks with the target connection's TLS
settings when forwarding through an HTTPS proxy.

``HTTPSConnection`` no longer applies target SNI, assertions, or client
credentials to forwarding proxy handshakes and continues to use its
``ssl_context`` as a fallback when an HTTPS proxy forwards an HTTP target.
(`5093 <https://github.com/urllib3/urllib3/issues/5093>`__)
- Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(`5095 <https://github.com/urllib3/urllib3/issues/5095>`__)
- Fixed an ``AttributeError`` on Python built with OpenSSL 4+, where
``ssl.PROTOCOL_TLSv1`` no longer exists.
(`5097 <https://github.com/urllib3/urllib3/issues/5097>`__)
- Fixed ``urllib3.contrib.pyopenssl`` to use cryptography APIs when reading a
certificate subject and loading encrypted private keys, avoiding
``DeprecationWarning`` raised by pyOpenSSL 26.3.0+.
(`5103 <https://github.com/urllib3/urllib3/issues/5103>`__)
- Fixed handling of HTTP 303 redirects for requests with chunked or file-like
bodies.
(`5161 <https://github.com/urllib3/urllib3/issues/5161>`__)
- Fixed ``assert_fingerprint()`` to raise ``SSLError`` instead of
``binascii.Error`` when a fingerprint has a supported length but contains
non-hexadecimal characters.
(`5211 <https://github.com/urllib3/urllib3/issues/5211>`__)


Misc
----

- Added a ``test`` dependency group containing the minimum dependencies needed
to run the test suite, intended for downstream packagers. The ``dev-base``
and ``mypy`` groups now include this new group via ``include-group``,
removing duplication.
(`3594 <https://github.com/urllib3/urllib3/issues/3594>`__)
- Fixed test failures with pytest >= 9.1.
(`5094 <https://github.com/urllib3/urllib3/issues/5094>`__)
- Enabled JSPI tests with Firefox in the Emscripten test suite.
(`5166 <https://github.com/urllib3/urllib3/issues/5166>`__)
- Improved streamed response decoding performance.
(`5209 <https://github.com/urllib3/urllib3/issues/5209>`__)
- Fixed flaky tests.
(`5232 <https://github.com/urllib3/urllib3/issues/5232>`__,
`5234 <https://github.com/urllib3/urllib3/issues/5234>`__,
`5239 <https://github.com/urllib3/urllib3/issues/5239>`__)

2.7.0

=======================

Security
--------

Addressed high-severity security issues.
Impact was limited to specific use cases detailed in the accompanying
advisories; overall user exposure was estimated to be marginal.

- Decompression-bomb safeguards of the streaming API were bypassed:

1. When ``HTTPResponse.drain_conn()`` was called after the response had been
  read and decompressed partially.
2. During the second ``HTTPResponse.read(amt=N)`` or
  ``HTTPResponse.stream(amt=N)`` call when the response was decompressed
  using the official `Brotli <https://pypi.org/project/brotli/>`__ library.

See `GHSA-mf9v-mfxr-j63j <https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j>`__
for details.

- HTTP pools created using ``ProxyManager.connection_from_url`` did not strip
sensitive headers specified in ``Retry.remove_headers_on_redirect`` when
redirecting to a different host.
(`GHSA-qccp-gfcp-xxvc <https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc>`__)


Deprecations and Removals
-------------------------

- Used ``FutureWarning`` instead of ``DeprecationWarning`` for better
visibility of existing deprecation notices. Rescheduled the removal of
deprecated features to version 3.0.
(`3763 <https://github.com/urllib3/urllib3/issues/3763>`__)
- Removed support for end-of-life Python 3.9.
(`3720 <https://github.com/urllib3/urllib3/issues/3720>`__)
- Removed support for end-of-life PyPy3.10.
(`4979 <https://github.com/urllib3/urllib3/issues/4979>`__)
- Bumped the minimum supported pyOpenSSL version to 19.0.0.
(`3777 <https://github.com/urllib3/urllib3/issues/3777>`__)


Bugfixes
--------

- Fixed a bug where ``HTTPResponse.read(amt=None)`` was ignoring decompressed
data buffered from previous partial reads.
(`3636 <https://github.com/urllib3/urllib3/issues/3636>`__)
- Fixed a bug where ``HTTPResponse.read()`` could cache only part of the
response after a partial read when ``cache_content=True``.
(`4967 <https://github.com/urllib3/urllib3/issues/4967>`__)
- Fixed ``HTTPResponse.stream()`` and ``HTTPResponse.read_chunked()`` to handle
``amt=0``.
(`3793 <https://github.com/urllib3/urllib3/issues/3793>`__)
- Updated ``_TYPE_BODY`` type alias to include missing ``Iterable[str]``,
matching the documented and runtime behavior of chunked request bodies.
(`3798 <https://github.com/urllib3/urllib3/issues/3798>`__)
- Fixed ``LocationParseError`` when paths resembling schemeless URIs were
passed to ``HTTPConnectionPool.urlopen()``.
(`3352 <https://github.com/urllib3/urllib3/issues/3352>`__)
- Fixed ``BaseHTTPResponse.readinto()`` type annotation to accept
``memoryview`` in addition to ``bytearray``, matching the
``io.RawIOBase.readinto`` contract and enabling use with
``io.BufferedReader`` without type errors.
(`3764 <https://github.com/urllib3/urllib3/issues/3764>`__)
Links

@pyup-bot pyup-bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant