CVE-2026-97687
Received Received - Intake

urllib3 HTTPS Proxy TLS Configuration Bypass

Vulnerability report for CVE-2026-97687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
urllib3 urllib3 From 1.26.0 (inc) to 2.8.0 (exc)
urllib3 urllib3 2.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-440 A feature, API, or function does not perform according to its specification.
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

urllib3 is a Python HTTP client library. From versions 1.26.0 to 2.8.0, certain TLS settings for target servers were incorrectly applied to HTTPS proxy connections. This caused proxy TLS settings to be overwritten, allowing attackers to intercept or modify forwarded traffic by impersonating the proxy.

Detection Guidance

Detection requires checking if your system uses urllib3 versions between 1.26.0 and 2.8.0 with HTTPS proxy configurations. Inspect installed urllib3 version using pip show urllib3 or python -c 'import urllib3; print(urllib3.__version__)'. Review application code for proxy settings like proxy_ssl_context, cert_reqs=CERT_NONE, or use_forwarding_for_https=True.

Impact Analysis

If you use an HTTPS proxy with urllib3 versions 1.26.0 to 2.8.0, an attacker could intercept or alter your traffic by impersonating the proxy. This could expose sensitive data or allow manipulation of your communications.

Compliance Impact

This vulnerability could lead to unauthorized interception or modification of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected urllib3 versions may face compliance violations.

Mitigation Strategies

Upgrade urllib3 to version 2.8.0 or later immediately. If upgrading is not possible, avoid using HTTPS proxies with target-server TLS settings that require separation. Disable cert_reqs=CERT_NONE in proxy configurations and ensure proxy_ssl_context is properly configured.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart