CVE-2026-97687: urllib3: HTTPS proxy TLS configuration may be ignored or overridden
urllib3 supports configuring TLS independently for an HTTPS proxy and the target server.
proxy_ssl_context, proxy_assert_hostname, and proxy_assert_fingerprint configure the TLS connection to the proxy. ssl_context and the other target-specific TLS parameters configure the connection to the target server.
In urllib3 versions 1.26.0 through 2.7.0, these configurations were not consistently separated. Depending on the proxy mode, urllib3 could:
- Ignore
proxy_ssl_contextand use the target server’s SSL context for the TLS connection to an HTTPS forwarding proxy. - Override the HTTPS proxy’s certificate-verification policy with the target server’s certificate-verification policy.
- Apply target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials to the TLS connection to an HTTPS forwarding proxy.
In particular, configuring cert_reqs="CERT_NONE" for a target server could overwrite the verify_mode of the SSL context configured for the HTTPS proxy. This modification occurred in place and persisted on the context object, potentially disabling proxy certificate verification for later connections that reused the same context.
An attacker able to intercept the connection to an HTTPS proxy may be able to impersonate the proxy when the effective proxy TLS configuration disables certificate verification or otherwise accepts the attacker’s certificate. This may occur, for example, when the target server’s trust or identity policy is incorrectly applied to the proxy connection.
When HTTPS forwarding is enabled, an impersonated proxy can observe or modify forwarded requests and responses, potentially exposing credentials, authentication tokens, request bodies, response data, and other sensitive information.
A TLS client certificate intended for the target server may also be presented to the proxy or to an attacker impersonating it. This can disclose the client’s identity and provide proof of possession of the corresponding private key. The private key itself is not transmitted during the TLS handshake.
In CONNECT tunneling mode, impersonating the HTTPS proxy does not by itself defeat the separate end-to-end TLS connection between the client and the target server.
References
- github.com/advisories/GHSA-8988-9cw3-xx77
- github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465
- github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3
- github.com/urllib3/urllib3/pull/5093
- github.com/urllib3/urllib3/releases/tag/2.8.0
- github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77
- nvd.nist.gov/vuln/detail/CVE-2026-97687
Code Behaviors & Features
Detect and mitigate CVE-2026-97687 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →