|
| 1 | +2.8.0 (2026-09-15) |
| 2 | +================== |
| 3 | + |
| 4 | +Security |
| 5 | +-------- |
| 6 | + |
| 7 | +Fixed the following security issues: |
| 8 | + |
| 9 | +- The TLS configuration for HTTPS proxies could be ignored or overridden. |
| 10 | + (High severity, `GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`__) |
| 11 | +- ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a chunk-size |
| 12 | + line of unbounded length in memory. (High severity, |
| 13 | + `GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`__) |
| 14 | +- Chunked Deflate streaming could enter an infinite loop. (Medium severity, |
| 15 | + `GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`__) |
| 16 | + |
| 17 | +.. caution:: |
| 18 | + |
| 19 | + urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or |
| 20 | + overridden by destination settings. Configurations relying on that |
| 21 | + behavior may require changes. |
| 22 | + |
| 23 | + Configure proxy CA certificates and client certificates in |
| 24 | + ``proxy_ssl_context``, and proxy identity checks with |
| 25 | + ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``. |
| 26 | + Destination client certificates and identity overrides no longer |
| 27 | + apply to HTTPS forwarding proxy connections. |
| 28 | + |
| 29 | + |
| 30 | +Deprecations & Removals |
| 31 | +----------------------- |
| 32 | + |
| 33 | +- Deprecated using an empty collection as the ``Retry`` option |
| 34 | + ``allowed_methods`` to retry any verb. |
| 35 | + (`#5044 <https://github.com/urllib3/urllib3/issues/5044>`__) |
| 36 | + |
| 37 | + |
| 38 | +Features |
| 39 | +-------- |
| 40 | + |
| 41 | +- Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined`` convenience |
| 42 | + properties to the result of ``parse_url()``. |
| 43 | + (`#4945 <https://github.com/urllib3/urllib3/issues/4945>`__) |
| 44 | +- Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding`` parameters to |
| 45 | + ``urllib3.util.make_headers()``. |
| 46 | + (`#5092 <https://github.com/urllib3/urllib3/issues/5092>`__) |
| 47 | + |
| 48 | + |
| 49 | +Bugfixes |
| 50 | +-------- |
| 51 | + |
| 52 | +- Fixed response header handling to replace obsolete folded header lines |
| 53 | + (`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF |
| 54 | + sequences from appearing in header values such as ``Set-Cookie``. |
| 55 | + (`#1362 <https://github.com/urllib3/urllib3/issues/1362>`__) |
| 56 | +- Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when |
| 57 | + ``use_forwarding_for_https=True``. Passing ``ssl_context`` instead of |
| 58 | + ``proxy_ssl_context`` for HTTPS proxies in this configuration now emits a |
| 59 | + ``FutureWarning`` and will raise an error in v3.0. |
| 60 | + (`#2577 <https://github.com/urllib3/urllib3/issues/2577>`__) |
| 61 | +- Changed behavior of the default ``ConnectionPool.pool`` initialization. |
| 62 | + ``LifoQueue`` is now resolved from the ``queue`` module after the |
| 63 | + ``ConnectionPool`` is instantiated instead of using the default cached |
| 64 | + ``QueueCls`` class property. This is done because sometimes the |
| 65 | + ``queue.LifoQueue`` is monkey-patched late in the program, such as by gevent. |
| 66 | + (`#3289 <https://github.com/urllib3/urllib3/issues/3289>`__) |
| 67 | +- Raised ``UnrewindableBodyError`` instead of ``ValueError`` when retrying a |
| 68 | + request whose body had ``tell()`` but not ``seek()``. |
| 69 | + (`#3779 <https://github.com/urllib3/urllib3/issues/3779>`__) |
| 70 | +- Decoded percent-encoded SOCKS proxy credentials before authenticating with |
| 71 | + the proxy server. |
| 72 | + (`#3785 <https://github.com/urllib3/urllib3/issues/3785>`__) |
| 73 | +- Fixed ``HTTPResponse.drain_conn()`` to discard unread response data in 64 KiB |
| 74 | + chunks (same as the default ``amt`` when doing ``HTTPResponse.stream(...)``). |
| 75 | + (`#5019 <https://github.com/urllib3/urllib3/issues/5019>`__) |
| 76 | +- Fixed ``is_ipaddress()`` to detect non-standard IPv4 forms accepted by |
| 77 | + ``socket.connect``, such as hex (``0x7f000001``), octal (``0177.0.0.1``), and |
| 78 | + decimal integers (``2130706433``), ensuring SSL certificate verification uses |
| 79 | + the correct mode for these addresses. |
| 80 | + (`#5029 <https://github.com/urllib3/urllib3/issues/5029>`__) |
| 81 | +- Fixed ``HTTPConnectionPool.urlopen`` raising a misleading ``FullPoolError`` |
| 82 | + instead of ``ValueError`` when called with an invalid ``timeout`` argument on |
| 83 | + a pool created with ``block=True``. |
| 84 | + (`#5059 <https://github.com/urllib3/urllib3/issues/5059>`__) |
| 85 | +- Fixed port-zero handling to preserve explicit ``:0`` values instead of |
| 86 | + substituting the default ports 80 or 443 in URL parsing, pool selection, |
| 87 | + proxy configuration, ``connection_from_url()``, and HTTP/2 request authority. |
| 88 | + (`#5071 <https://github.com/urllib3/urllib3/issues/5071>`__, |
| 89 | + `#5101 <https://github.com/urllib3/urllib3/issues/5101>`__) |
| 90 | +- Fixed a bug where ``PoolManager`` passed the ``assert_hostname`` and |
| 91 | + ``assert_fingerprint`` parameters to HTTP connection pools. |
| 92 | + (`#5077 <https://github.com/urllib3/urllib3/issues/5077>`__) |
| 93 | +- Fixed ``HTTPConnectionPool.urlopen()`` and HTTP proxy forwarding to strip URL |
| 94 | + fragments from absolute request targets before sending requests. |
| 95 | + (`#5079 <https://github.com/urllib3/urllib3/issues/5079>`__) |
| 96 | +- Added safeguards to the proxy tunneling code to prevent potential security |
| 97 | + issues when handling invalid characters in the proxy host and HTTP headers. |
| 98 | + This change affects users of Python 3.10, Python 3.11, and Python 3.12 when |
| 99 | + the standard library does not contain the fix; those on newer Python versions |
| 100 | + should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. |
| 101 | + (`#5091 <https://github.com/urllib3/urllib3/issues/5091>`__) |
| 102 | +- Fixed ``HTTPSConnection.connect()`` overriding ``ProxyConfig.ssl_context``'s |
| 103 | + certificate policy and proxy identity checks with the target connection's TLS |
| 104 | + settings when forwarding through an HTTPS proxy. |
| 105 | + |
| 106 | + ``HTTPSConnection`` no longer applies target SNI, assertions, or client |
| 107 | + credentials to forwarding proxy handshakes and continues to use its |
| 108 | + ``ssl_context`` as a fallback when an HTTPS proxy forwards an HTTP target. |
| 109 | + (`#5093 <https://github.com/urllib3/urllib3/issues/5093>`__) |
| 110 | +- Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting |
| 111 | + invalid host input such as raw spaces and control characters, malformed |
| 112 | + percent-encodings, and percent-encoded control characters in HTTP(S) hosts |
| 113 | + and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host |
| 114 | + normalization now also follows RFC 3986 normalization rules for |
| 115 | + percent-encoded octets by decoding percent-encoded unreserved characters and |
| 116 | + uppercasing the hexadecimal digits of retained percent-encoded octets. |
| 117 | + (`#5095 <https://github.com/urllib3/urllib3/issues/5095>`__) |
| 118 | +- Fixed an ``AttributeError`` on Python built with OpenSSL 4+, where |
| 119 | + ``ssl.PROTOCOL_TLSv1`` no longer exists. |
| 120 | + (`#5097 <https://github.com/urllib3/urllib3/issues/5097>`__) |
| 121 | +- Fixed ``urllib3.contrib.pyopenssl`` to use cryptography APIs when reading a |
| 122 | + certificate subject and loading encrypted private keys, avoiding |
| 123 | + ``DeprecationWarning`` raised by pyOpenSSL 26.3.0+. |
| 124 | + (`#5103 <https://github.com/urllib3/urllib3/issues/5103>`__) |
| 125 | +- Fixed handling of HTTP 303 redirects for requests with chunked or file-like |
| 126 | + bodies. |
| 127 | + (`#5161 <https://github.com/urllib3/urllib3/issues/5161>`__) |
| 128 | +- Fixed ``assert_fingerprint()`` to raise ``SSLError`` instead of |
| 129 | + ``binascii.Error`` when a fingerprint has a supported length but contains |
| 130 | + non-hexadecimal characters. |
| 131 | + (`#5211 <https://github.com/urllib3/urllib3/issues/5211>`__) |
| 132 | + |
| 133 | + |
| 134 | +Misc |
| 135 | +---- |
| 136 | + |
| 137 | +- Added a ``test`` dependency group containing the minimum dependencies needed |
| 138 | + to run the test suite, intended for downstream packagers. The ``dev-base`` |
| 139 | + and ``mypy`` groups now include this new group via ``include-group``, |
| 140 | + removing duplication. |
| 141 | + (`#3594 <https://github.com/urllib3/urllib3/issues/3594>`__) |
| 142 | +- Fixed test failures with pytest >= 9.1. |
| 143 | + (`#5094 <https://github.com/urllib3/urllib3/issues/5094>`__) |
| 144 | +- Enabled JSPI tests with Firefox in the Emscripten test suite. |
| 145 | + (`#5166 <https://github.com/urllib3/urllib3/issues/5166>`__) |
| 146 | +- Improved streamed response decoding performance. |
| 147 | + (`#5209 <https://github.com/urllib3/urllib3/issues/5209>`__) |
| 148 | +- Fixed flaky tests. |
| 149 | + (`#5232 <https://github.com/urllib3/urllib3/issues/5232>`__, |
| 150 | + `#5234 <https://github.com/urllib3/urllib3/issues/5234>`__, |
| 151 | + `#5239 <https://github.com/urllib3/urllib3/issues/5239>`__) |
| 152 | + |
| 153 | + |
1 | 154 | 2.7.0 (2026-05-07) |
2 | 155 | ======================= |
3 | 156 |
|
|
0 commit comments