The TLS configuration for HTTPS proxies could be ignored or overridden.
(High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
HTTPResponse.stream() and read_chunked() could buffer a chunk-size
line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)
.. caution::
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
Configure proxy CA certificates and client certificates in
``proxy_ssl_context``, and proxy identity checks with
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
Deprecations & Removals
Deprecated using an empty collection as the Retry option allowed_methods to retry any verb.
(#​5044 <https://github.com/urllib3/urllib3/issues/5044>__)
Features
Added Url.auth_decoded and Url.auth_decoded_joined convenience
properties to the result of parse_url().
(#​4945 <https://github.com/urllib3/urllib3/issues/4945>__)
Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers().
(#​5092 <https://github.com/urllib3/urllib3/issues/5092>__)
Bugfixes
Fixed response header handling to replace obsolete folded header lines
(obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF
sequences from appearing in header values such as Set-Cookie.
(#​1362 <https://github.com/urllib3/urllib3/issues/1362>__)
Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0.
(#​2577 <https://github.com/urllib3/urllib3/issues/2577>__)
Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent.
(#​3289 <https://github.com/urllib3/urllib3/issues/3289>__)
Raised UnrewindableBodyError instead of ValueError when retrying a
request whose body had tell() but not seek().
(#​3779 <https://github.com/urllib3/urllib3/issues/3779>__)
Decoded percent-encoded SOCKS proxy credentials before authenticating with
the proxy server.
(#​3785 <https://github.com/urllib3/urllib3/issues/3785>__)
Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB
chunks (same as the default amt when doing HTTPResponse.stream(...)).
(#​5019 <https://github.com/urllib3/urllib3/issues/5019>__)
Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and
decimal integers (2130706433), ensuring SSL certificate verification uses
the correct mode for these addresses.
(#​5029 <https://github.com/urllib3/urllib3/issues/5029>__)
Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError
instead of ValueError when called with an invalid timeout argument on
a pool created with block=True.
(#​5059 <https://github.com/urllib3/urllib3/issues/5059>__)
Fixed port-zero handling to preserve explicit :0 values instead of
substituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration, connection_from_url(), and HTTP/2 request authority.
(#​5071 <https://github.com/urllib3/urllib3/issues/5071>, #​5101 <https://github.com/urllib3/urllib3/issues/5101>)
Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools.
(#​5077 <https://github.com/urllib3/urllib3/issues/5077>__)
Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL
fragments from absolute request targets before sending requests.
(#​5079 <https://github.com/urllib3/urllib3/issues/5079>__)
Added safeguards to the proxy tunneling code to prevent potential security
issues when handling invalid characters in the proxy host and HTTP headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
the standard library does not contain the fix; those on newer Python versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(#​5091 <https://github.com/urllib3/urllib3/issues/5091>__)
Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's
certificate policy and proxy identity checks with the target connection's TLS
settings when forwarding through an HTTPS proxy.
HTTPSConnection no longer applies target SNI, assertions, or client
credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target.
(#​5093 <https://github.com/urllib3/urllib3/issues/5093>__)
Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(#​5095 <https://github.com/urllib3/urllib3/issues/5095>__)
Fixed an AttributeError on Python built with OpenSSL 4+, where ssl.PROTOCOL_TLSv1 no longer exists.
(#​5097 <https://github.com/urllib3/urllib3/issues/5097>__)
Fixed urllib3.contrib.pyopenssl to use cryptography APIs when reading a
certificate subject and loading encrypted private keys, avoiding DeprecationWarning raised by pyOpenSSL 26.3.0+.
(#​5103 <https://github.com/urllib3/urllib3/issues/5103>__)
Fixed handling of HTTP 303 redirects for requests with chunked or file-like
bodies.
(#​5161 <https://github.com/urllib3/urllib3/issues/5161>__)
Fixed assert_fingerprint() to raise SSLError instead of binascii.Error when a fingerprint has a supported length but contains
non-hexadecimal characters.
(#​5211 <https://github.com/urllib3/urllib3/issues/5211>__)
Misc
Added a test dependency group containing the minimum dependencies needed
to run the test suite, intended for downstream packagers. The dev-base
and mypy groups now include this new group via include-group,
removing duplication.
(#​3594 <https://github.com/urllib3/urllib3/issues/3594>__)
Fixed test failures with pytest >= 9.1.
(#​5094 <https://github.com/urllib3/urllib3/issues/5094>__)
Enabled JSPI tests with Firefox in the Emscripten test suite.
(#​5166 <https://github.com/urllib3/urllib3/issues/5166>__)
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [urllib3](https://github.com/urllib3/urllib3) ([changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)) | minor | `==2.7.0` → `==2.8.0` |
---
### Release Notes
<details>
<summary>urllib3/urllib3 (urllib3)</summary>
### [`v2.8.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#280-2026-09-15)
[Compare Source](https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0)
\==================
## Security
Fixed the following security issues:
- The TLS configuration for HTTPS proxies could be ignored or overridden.
(High severity, `GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`\_\_)
- `HTTPResponse.stream()` and `read_chunked()` could buffer a chunk-size
line of unbounded length in memory. (High severity,
`GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`\_\_)
- Chunked Deflate streaming could enter an infinite loop. (Medium severity,
`GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`\_\_)
.. caution::
```
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
Configure proxy CA certificates and client certificates in
``proxy_ssl_context``, and proxy identity checks with
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
```
## Deprecations & Removals
- Deprecated using an empty collection as the `Retry` option
`allowed_methods` to retry any verb.
(`#​5044 <https://github.com/urllib3/urllib3/issues/5044>`\_\_)
## Features
- Added `Url.auth_decoded` and `Url.auth_decoded_joined` convenience
properties to the result of `parse_url()`.
(`#​4945 <https://github.com/urllib3/urllib3/issues/4945>`\_\_)
- Added `basic_auth_encoding` and `proxy_basic_auth_encoding` parameters to
`urllib3.util.make_headers()`.
(`#​5092 <https://github.com/urllib3/urllib3/issues/5092>`\_\_)
## Bugfixes
- Fixed response header handling to replace obsolete folded header lines
(`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF
sequences from appearing in header values such as `Set-Cookie`.
(`#​1362 <https://github.com/urllib3/urllib3/issues/1362>`\_\_)
- Fixed usage of `proxy_ssl_context` with `ProxyManager` when
`use_forwarding_for_https=True`. Passing `ssl_context` instead of
`proxy_ssl_context` for HTTPS proxies in this configuration now emits a
`FutureWarning` and will raise an error in v3.0.
(`#​2577 <https://github.com/urllib3/urllib3/issues/2577>`\_\_)
- Changed behavior of the default `ConnectionPool.pool` initialization.
`LifoQueue` is now resolved from the `queue` module after the
`ConnectionPool` is instantiated instead of using the default cached
`QueueCls` class property. This is done because sometimes the
`queue.LifoQueue` is monkey-patched late in the program, such as by gevent.
(`#​3289 <https://github.com/urllib3/urllib3/issues/3289>`\_\_)
- Raised `UnrewindableBodyError` instead of `ValueError` when retrying a
request whose body had `tell()` but not `seek()`.
(`#​3779 <https://github.com/urllib3/urllib3/issues/3779>`\_\_)
- Decoded percent-encoded SOCKS proxy credentials before authenticating with
the proxy server.
(`#​3785 <https://github.com/urllib3/urllib3/issues/3785>`\_\_)
- Fixed `HTTPResponse.drain_conn()` to discard unread response data in 64 KiB
chunks (same as the default `amt` when doing `HTTPResponse.stream(...)`).
(`#​5019 <https://github.com/urllib3/urllib3/issues/5019>`\_\_)
- Fixed `is_ipaddress()` to detect non-standard IPv4 forms accepted by
`socket.connect`, such as hex (`0x7f000001`), octal (`0177.0.0.1`), and
decimal integers (`2130706433`), ensuring SSL certificate verification uses
the correct mode for these addresses.
(`#​5029 <https://github.com/urllib3/urllib3/issues/5029>`\_\_)
- Fixed `HTTPConnectionPool.urlopen` raising a misleading `FullPoolError`
instead of `ValueError` when called with an invalid `timeout` argument on
a pool created with `block=True`.
(`#​5059 <https://github.com/urllib3/urllib3/issues/5059>`\_\_)
- Fixed port-zero handling to preserve explicit `:0` values instead of
substituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration, `connection_from_url()`, and HTTP/2 request authority.
(`#​5071 <https://github.com/urllib3/urllib3/issues/5071>`**,
`#​5101 <https://github.com/urllib3/urllib3/issues/5101>`**)
- Fixed a bug where `PoolManager` passed the `assert_hostname` and
`assert_fingerprint` parameters to HTTP connection pools.
(`#​5077 <https://github.com/urllib3/urllib3/issues/5077>`\_\_)
- Fixed `HTTPConnectionPool.urlopen()` and HTTP proxy forwarding to strip URL
fragments from absolute request targets before sending requests.
(`#​5079 <https://github.com/urllib3/urllib3/issues/5079>`\_\_)
- Added safeguards to the proxy tunneling code to prevent potential security
issues when handling invalid characters in the proxy host and HTTP headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
the standard library does not contain the fix; those on newer Python versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(`#​5091 <https://github.com/urllib3/urllib3/issues/5091>`\_\_)
- Fixed `HTTPSConnection.connect()` overriding `ProxyConfig.ssl_context`'s
certificate policy and proxy identity checks with the target connection's TLS
settings when forwarding through an HTTPS proxy.
`HTTPSConnection` no longer applies target SNI, assertions, or client
credentials to forwarding proxy handshakes and continues to use its
`ssl_context` as a fallback when an HTTPS proxy forwards an HTTP target.
(`#​5093 <https://github.com/urllib3/urllib3/issues/5093>`\_\_)
- Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(`#​5095 <https://github.com/urllib3/urllib3/issues/5095>`\_\_)
- Fixed an `AttributeError` on Python built with OpenSSL 4+, where
`ssl.PROTOCOL_TLSv1` no longer exists.
(`#​5097 <https://github.com/urllib3/urllib3/issues/5097>`\_\_)
- Fixed `urllib3.contrib.pyopenssl` to use cryptography APIs when reading a
certificate subject and loading encrypted private keys, avoiding
`DeprecationWarning` raised by pyOpenSSL 26.3.0+.
(`#​5103 <https://github.com/urllib3/urllib3/issues/5103>`\_\_)
- Fixed handling of HTTP 303 redirects for requests with chunked or file-like
bodies.
(`#​5161 <https://github.com/urllib3/urllib3/issues/5161>`\_\_)
- Fixed `assert_fingerprint()` to raise `SSLError` instead of
`binascii.Error` when a fingerprint has a supported length but contains
non-hexadecimal characters.
(`#​5211 <https://github.com/urllib3/urllib3/issues/5211>`\_\_)
## Misc
- Added a `test` dependency group containing the minimum dependencies needed
to run the test suite, intended for downstream packagers. The `dev-base`
and `mypy` groups now include this new group via `include-group`,
removing duplication.
(`#​3594 <https://github.com/urllib3/urllib3/issues/3594>`\_\_)
- Fixed test failures with pytest >= 9.1.
(`#​5094 <https://github.com/urllib3/urllib3/issues/5094>`\_\_)
- Enabled JSPI tests with Firefox in the Emscripten test suite.
(`#​5166 <https://github.com/urllib3/urllib3/issues/5166>`\_\_)
- Improved streamed response decoding performance.
(`#​5209 <https://github.com/urllib3/urllib3/issues/5209>`\_\_)
- Fixed flaky tests.
(`#​5232 <https://github.com/urllib3/urllib3/issues/5232>`**,
`#​5234 <https://github.com/urllib3/urllib3/issues/5234>`**,
`#​5239 <https://github.com/urllib3/urllib3/issues/5239>`\_\_)
</details>
---
### Configuration
📅 **Schedule**: (in timezone America/Edmonton)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC45My40IiwidXBkYXRlZEluVmVyIjoiNDQuOTMuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
==2.7.0→==2.8.0Release Notes
urllib3/urllib3 (urllib3)
v2.8.0Compare Source
==================
Security
Fixed the following security issues:
(High severity,
GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)HTTPResponse.stream()andread_chunked()could buffer a chunk-sizeline of unbounded length in memory. (High severity,
GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__).. caution::
Deprecations & Removals
Retryoptionallowed_methodsto retry any verb.(
#​5044 <https://github.com/urllib3/urllib3/issues/5044>__)Features
Url.auth_decodedandUrl.auth_decoded_joinedconvenienceproperties to the result of
parse_url().(
#​4945 <https://github.com/urllib3/urllib3/issues/4945>__)basic_auth_encodingandproxy_basic_auth_encodingparameters tourllib3.util.make_headers().(
#​5092 <https://github.com/urllib3/urllib3/issues/5092>__)Bugfixes
Fixed response header handling to replace obsolete folded header lines
(
obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLFsequences from appearing in header values such as
Set-Cookie.(
#​1362 <https://github.com/urllib3/urllib3/issues/1362>__)Fixed usage of
proxy_ssl_contextwithProxyManagerwhenuse_forwarding_for_https=True. Passingssl_contextinstead ofproxy_ssl_contextfor HTTPS proxies in this configuration now emits aFutureWarningand will raise an error in v3.0.(
#​2577 <https://github.com/urllib3/urllib3/issues/2577>__)Changed behavior of the default
ConnectionPool.poolinitialization.LifoQueueis now resolved from thequeuemodule after theConnectionPoolis instantiated instead of using the default cachedQueueClsclass property. This is done because sometimes thequeue.LifoQueueis monkey-patched late in the program, such as by gevent.(
#​3289 <https://github.com/urllib3/urllib3/issues/3289>__)Raised
UnrewindableBodyErrorinstead ofValueErrorwhen retrying arequest whose body had
tell()but notseek().(
#​3779 <https://github.com/urllib3/urllib3/issues/3779>__)Decoded percent-encoded SOCKS proxy credentials before authenticating with
the proxy server.
(
#​3785 <https://github.com/urllib3/urllib3/issues/3785>__)Fixed
HTTPResponse.drain_conn()to discard unread response data in 64 KiBchunks (same as the default
amtwhen doingHTTPResponse.stream(...)).(
#​5019 <https://github.com/urllib3/urllib3/issues/5019>__)Fixed
is_ipaddress()to detect non-standard IPv4 forms accepted bysocket.connect, such as hex (0x7f000001), octal (0177.0.0.1), anddecimal integers (
2130706433), ensuring SSL certificate verification usesthe correct mode for these addresses.
(
#​5029 <https://github.com/urllib3/urllib3/issues/5029>__)Fixed
HTTPConnectionPool.urlopenraising a misleadingFullPoolErrorinstead of
ValueErrorwhen called with an invalidtimeoutargument ona pool created with
block=True.(
#​5059 <https://github.com/urllib3/urllib3/issues/5059>__)Fixed port-zero handling to preserve explicit
:0values instead ofsubstituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration,
connection_from_url(), and HTTP/2 request authority.(
#​5071 <https://github.com/urllib3/urllib3/issues/5071>,#​5101 <https://github.com/urllib3/urllib3/issues/5101>)Fixed a bug where
PoolManagerpassed theassert_hostnameandassert_fingerprintparameters to HTTP connection pools.(
#​5077 <https://github.com/urllib3/urllib3/issues/5077>__)Fixed
HTTPConnectionPool.urlopen()and HTTP proxy forwarding to strip URLfragments from absolute request targets before sending requests.
(
#​5079 <https://github.com/urllib3/urllib3/issues/5079>__)Added safeguards to the proxy tunneling code to prevent potential security
issues when handling invalid characters in the proxy host and HTTP headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
the standard library does not contain the fix; those on newer Python versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(
#​5091 <https://github.com/urllib3/urllib3/issues/5091>__)Fixed
HTTPSConnection.connect()overridingProxyConfig.ssl_context'scertificate policy and proxy identity checks with the target connection's TLS
settings when forwarding through an HTTPS proxy.
HTTPSConnectionno longer applies target SNI, assertions, or clientcredentials to forwarding proxy handshakes and continues to use its
ssl_contextas a fallback when an HTTPS proxy forwards an HTTP target.(
#​5093 <https://github.com/urllib3/urllib3/issues/5093>__)Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(
#​5095 <https://github.com/urllib3/urllib3/issues/5095>__)Fixed an
AttributeErroron Python built with OpenSSL 4+, wheressl.PROTOCOL_TLSv1no longer exists.(
#​5097 <https://github.com/urllib3/urllib3/issues/5097>__)Fixed
urllib3.contrib.pyopensslto use cryptography APIs when reading acertificate subject and loading encrypted private keys, avoiding
DeprecationWarningraised by pyOpenSSL 26.3.0+.(
#​5103 <https://github.com/urllib3/urllib3/issues/5103>__)Fixed handling of HTTP 303 redirects for requests with chunked or file-like
bodies.
(
#​5161 <https://github.com/urllib3/urllib3/issues/5161>__)Fixed
assert_fingerprint()to raiseSSLErrorinstead ofbinascii.Errorwhen a fingerprint has a supported length but containsnon-hexadecimal characters.
(
#​5211 <https://github.com/urllib3/urllib3/issues/5211>__)Misc
testdependency group containing the minimum dependencies neededto run the test suite, intended for downstream packagers. The
dev-baseand
mypygroups now include this new group viainclude-group,removing duplication.
(
#​3594 <https://github.com/urllib3/urllib3/issues/3594>__)(
#​5094 <https://github.com/urllib3/urllib3/issues/5094>__)(
#​5166 <https://github.com/urllib3/urllib3/issues/5166>__)(
#​5209 <https://github.com/urllib3/urllib3/issues/5209>__)(
#​5232 <https://github.com/urllib3/urllib3/issues/5232>,#​5234 <https://github.com/urllib3/urllib3/issues/5234>,#​5239 <https://github.com/urllib3/urllib3/issues/5239>__)Configuration
📅 Schedule: (in timezone America/Edmonton)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.