Skip to content
Threat Feed
medium advisory

urllib3 HTTPS Proxy TLS Configuration Misisolation

urllib3 versions 1.26.0 through 2.7.0 fail to properly isolate TLS configurations between HTTPS proxies and target servers, enabling potential man-in-the-middle attacks through certificate verification bypass or credential exposure.

CVE search metadata

CVE search record: CVE-2026-97687. KEV: no. Product: urllib3 (>= 1.26.0, < 2.8.0). Brief: urllib3 HTTPS Proxy TLS Configuration Misisolation. Brief link: https://feed.craftedsignal.io/briefs/2026-09-urllib3-tls-proxy-misconfiguration/

The Python library urllib3, in versions 1.26.0 through 2.7.0, contains a vulnerability (CVE-2026-97687) regarding the separation of TLS configurations for HTTPS proxies and target servers. The library incorrectly allows settings intended for the destination server - such as SNI, hostname assertions, certificate fingerprints, or client certificates - to be applied to the TLS handshake with the HTTPS proxy.

Furthermore, the library performs in-place mutation of SSL context objects when certificate verification is disabled for a target (e.g., using cert_reqs="CERT_NONE"). Because this mutation is applied to the context object directly, these changes can persist and be applied to subsequent connections that reuse the same context, effectively disabling certificate verification for the proxy connection as well. An attacker capable of intercepting traffic to the HTTPS proxy can leverage these misconfigurations to impersonate the proxy, intercepting sensitive data, authentication tokens, or observing forwarded request bodies.

Impact

Successful exploitation allows an attacker to perform man-in-the-middle attacks on HTTPS traffic forwarded through a proxy. This exposes sensitive information, including request/response bodies, credentials, and authentication tokens. Additionally, a client certificate intended for a target server might be improperly presented to the proxy or an attacker, leading to the disclosure of the client's identity and providing proof of possession of the client's private key.

Recommendation

Prioritize the upgrade of all applications utilizing the affected versions of urllib3.

  • Upgrade to urllib3 2.8.0 or later to ensure proper isolation of proxy and target SSL contexts.
  • Update codebases to use the proxy_ssl_context parameter for configuring TLS on HTTPS forwarding proxies rather than relying on global or target-specific ssl_context objects.
  • Review applications using use_forwarding_for_https=True to ensure they are not passing a shared ssl_context that may be mutated in-place during target-specific certificate verification.
  • Monitor for FutureWarning messages generated by urllib3 2.8.0, which indicate legacy configurations that will be deprecated and produce errors in urllib3 3.0.

Mitigations

Upgrade urllib3 to 2.8.0 or later across all environments

immediate Software Engineering

CVE-2026-97687