Skip to content

Commit b1d30ab

Browse files
authored
Release 2.8.0
1 parent 9016d7e commit b1d30ab

32 files changed

Lines changed: 153 additions & 60 deletions

‎CHANGES.rst‎

Lines changed: 153 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,156 @@
1+
2.8.0 (2026-09-15)
2+
==================
3+
4+
Security
5+
--------
6+
7+
Fixed the following security issues:
8+
9+
- The TLS configuration for HTTPS proxies could be ignored or overridden.
10+
(High severity, `GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`__)
11+
- ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a chunk-size
12+
line of unbounded length in memory. (High severity,
13+
`GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`__)
14+
- Chunked Deflate streaming could enter an infinite loop. (Medium severity,
15+
`GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`__)
16+
17+
.. caution::
18+
19+
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
20+
overridden by destination settings. Configurations relying on that
21+
behavior may require changes.
22+
23+
Configure proxy CA certificates and client certificates in
24+
``proxy_ssl_context``, and proxy identity checks with
25+
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
26+
Destination client certificates and identity overrides no longer
27+
apply to HTTPS forwarding proxy connections.
28+
29+
30+
Deprecations & Removals
31+
-----------------------
32+
33+
- Deprecated using an empty collection as the ``Retry`` option
34+
``allowed_methods`` to retry any verb.
35+
(`#5044 <https://github.com/urllib3/urllib3/issues/5044>`__)
36+
37+
38+
Features
39+
--------
40+
41+
- Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined`` convenience
42+
properties to the result of ``parse_url()``.
43+
(`#4945 <https://github.com/urllib3/urllib3/issues/4945>`__)
44+
- Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding`` parameters to
45+
``urllib3.util.make_headers()``.
46+
(`#5092 <https://github.com/urllib3/urllib3/issues/5092>`__)
47+
48+
49+
Bugfixes
50+
--------
51+
52+
- Fixed response header handling to replace obsolete folded header lines
53+
(`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF
54+
sequences from appearing in header values such as ``Set-Cookie``.
55+
(`#1362 <https://github.com/urllib3/urllib3/issues/1362>`__)
56+
- Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when
57+
``use_forwarding_for_https=True``. Passing ``ssl_context`` instead of
58+
``proxy_ssl_context`` for HTTPS proxies in this configuration now emits a
59+
``FutureWarning`` and will raise an error in v3.0.
60+
(`#2577 <https://github.com/urllib3/urllib3/issues/2577>`__)
61+
- Changed behavior of the default ``ConnectionPool.pool`` initialization.
62+
``LifoQueue`` is now resolved from the ``queue`` module after the
63+
``ConnectionPool`` is instantiated instead of using the default cached
64+
``QueueCls`` class property. This is done because sometimes the
65+
``queue.LifoQueue`` is monkey-patched late in the program, such as by gevent.
66+
(`#3289 <https://github.com/urllib3/urllib3/issues/3289>`__)
67+
- Raised ``UnrewindableBodyError`` instead of ``ValueError`` when retrying a
68+
request whose body had ``tell()`` but not ``seek()``.
69+
(`#3779 <https://github.com/urllib3/urllib3/issues/3779>`__)
70+
- Decoded percent-encoded SOCKS proxy credentials before authenticating with
71+
the proxy server.
72+
(`#3785 <https://github.com/urllib3/urllib3/issues/3785>`__)
73+
- Fixed ``HTTPResponse.drain_conn()`` to discard unread response data in 64 KiB
74+
chunks (same as the default ``amt`` when doing ``HTTPResponse.stream(...)``).
75+
(`#5019 <https://github.com/urllib3/urllib3/issues/5019>`__)
76+
- Fixed ``is_ipaddress()`` to detect non-standard IPv4 forms accepted by
77+
``socket.connect``, such as hex (``0x7f000001``), octal (``0177.0.0.1``), and
78+
decimal integers (``2130706433``), ensuring SSL certificate verification uses
79+
the correct mode for these addresses.
80+
(`#5029 <https://github.com/urllib3/urllib3/issues/5029>`__)
81+
- Fixed ``HTTPConnectionPool.urlopen`` raising a misleading ``FullPoolError``
82+
instead of ``ValueError`` when called with an invalid ``timeout`` argument on
83+
a pool created with ``block=True``.
84+
(`#5059 <https://github.com/urllib3/urllib3/issues/5059>`__)
85+
- Fixed port-zero handling to preserve explicit ``:0`` values instead of
86+
substituting the default ports 80 or 443 in URL parsing, pool selection,
87+
proxy configuration, ``connection_from_url()``, and HTTP/2 request authority.
88+
(`#5071 <https://github.com/urllib3/urllib3/issues/5071>`__,
89+
`#5101 <https://github.com/urllib3/urllib3/issues/5101>`__)
90+
- Fixed a bug where ``PoolManager`` passed the ``assert_hostname`` and
91+
``assert_fingerprint`` parameters to HTTP connection pools.
92+
(`#5077 <https://github.com/urllib3/urllib3/issues/5077>`__)
93+
- Fixed ``HTTPConnectionPool.urlopen()`` and HTTP proxy forwarding to strip URL
94+
fragments from absolute request targets before sending requests.
95+
(`#5079 <https://github.com/urllib3/urllib3/issues/5079>`__)
96+
- Added safeguards to the proxy tunneling code to prevent potential security
97+
issues when handling invalid characters in the proxy host and HTTP headers.
98+
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
99+
the standard library does not contain the fix; those on newer Python versions
100+
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
101+
(`#5091 <https://github.com/urllib3/urllib3/issues/5091>`__)
102+
- Fixed ``HTTPSConnection.connect()`` overriding ``ProxyConfig.ssl_context``'s
103+
certificate policy and proxy identity checks with the target connection's TLS
104+
settings when forwarding through an HTTPS proxy.
105+
106+
``HTTPSConnection`` no longer applies target SNI, assertions, or client
107+
credentials to forwarding proxy handshakes and continues to use its
108+
``ssl_context`` as a fallback when an HTTPS proxy forwards an HTTP target.
109+
(`#5093 <https://github.com/urllib3/urllib3/issues/5093>`__)
110+
- Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
111+
invalid host input such as raw spaces and control characters, malformed
112+
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
113+
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
114+
normalization now also follows RFC 3986 normalization rules for
115+
percent-encoded octets by decoding percent-encoded unreserved characters and
116+
uppercasing the hexadecimal digits of retained percent-encoded octets.
117+
(`#5095 <https://github.com/urllib3/urllib3/issues/5095>`__)
118+
- Fixed an ``AttributeError`` on Python built with OpenSSL 4+, where
119+
``ssl.PROTOCOL_TLSv1`` no longer exists.
120+
(`#5097 <https://github.com/urllib3/urllib3/issues/5097>`__)
121+
- Fixed ``urllib3.contrib.pyopenssl`` to use cryptography APIs when reading a
122+
certificate subject and loading encrypted private keys, avoiding
123+
``DeprecationWarning`` raised by pyOpenSSL 26.3.0+.
124+
(`#5103 <https://github.com/urllib3/urllib3/issues/5103>`__)
125+
- Fixed handling of HTTP 303 redirects for requests with chunked or file-like
126+
bodies.
127+
(`#5161 <https://github.com/urllib3/urllib3/issues/5161>`__)
128+
- Fixed ``assert_fingerprint()`` to raise ``SSLError`` instead of
129+
``binascii.Error`` when a fingerprint has a supported length but contains
130+
non-hexadecimal characters.
131+
(`#5211 <https://github.com/urllib3/urllib3/issues/5211>`__)
132+
133+
134+
Misc
135+
----
136+
137+
- Added a ``test`` dependency group containing the minimum dependencies needed
138+
to run the test suite, intended for downstream packagers. The ``dev-base``
139+
and ``mypy`` groups now include this new group via ``include-group``,
140+
removing duplication.
141+
(`#3594 <https://github.com/urllib3/urllib3/issues/3594>`__)
142+
- Fixed test failures with pytest >= 9.1.
143+
(`#5094 <https://github.com/urllib3/urllib3/issues/5094>`__)
144+
- Enabled JSPI tests with Firefox in the Emscripten test suite.
145+
(`#5166 <https://github.com/urllib3/urllib3/issues/5166>`__)
146+
- Improved streamed response decoding performance.
147+
(`#5209 <https://github.com/urllib3/urllib3/issues/5209>`__)
148+
- Fixed flaky tests.
149+
(`#5232 <https://github.com/urllib3/urllib3/issues/5232>`__,
150+
`#5234 <https://github.com/urllib3/urllib3/issues/5234>`__,
151+
`#5239 <https://github.com/urllib3/urllib3/issues/5239>`__)
152+
153+
1154
2.7.0 (2026-05-07)
2155
=======================
3156

‎changelog/1362.bugfix.rst‎

Lines changed: 0 additions & 3 deletions
This file was deleted.

‎changelog/2577.bugfix.rst‎

Lines changed: 0 additions & 2 deletions
This file was deleted.

‎changelog/3289.bugfix.rst‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎changelog/3594.feature.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

‎changelog/3779.bugfix.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

‎changelog/3785.bugfix.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

‎changelog/4945.feature.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

‎changelog/5019.bugfix.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

‎changelog/5029.bugfix.rst‎

Lines changed: 0 additions & 4 deletions
This file was deleted.

0 commit comments

Comments
 (0)