urllib3 HTTPS Proxy TLS Configuration Misisolation
urllib3 versions 1.26.0 through 2.7.0 fail to properly isolate TLS configurations between HTTPS proxies and target servers, enabling potential man-in-the-middle attacks through certificate verification bypass or credential exposure.
CVE search metadata
CVE search record: CVE-2026-97687. KEV: no. Product: urllib3 (>= 1.26.0, < 2.8.0). Brief: urllib3 HTTPS Proxy TLS Configuration Misisolation. Brief link: https://feed.craftedsignal.io/briefs/2026-09-urllib3-tls-proxy-misconfiguration/
The Python library urllib3, in versions 1.26.0 through 2.7.0, contains a vulnerability (CVE-2026-97687) regarding the separation of TLS configurations for HTTPS proxies and target servers. The library incorrectly allows settings intended for the destination server - such as SNI, hostname assertions, certificate fingerprints, or client certificates - to be applied to the TLS handshake with the HTTPS proxy.
Furthermore, the library performs in-place mutation of SSL context objects when certificate verification is disabled for a target (e.g., using cert_reqs="CERT_NONE"). Because this mutation is applied to the context object directly, these changes can persist and be applied to subsequent connections that reuse the same context, effectively disabling certificate verification for the proxy connection as well. An attacker capable of intercepting traffic to the HTTPS proxy can leverage these misconfigurations to impersonate the proxy, intercepting sensitive data, authentication tokens, or observing forwarded request bodies.
Impact
Successful exploitation allows an attacker to perform man-in-the-middle attacks on HTTPS traffic forwarded through a proxy. This exposes sensitive information, including request/response bodies, credentials, and authentication tokens. Additionally, a client certificate intended for a target server might be improperly presented to the proxy or an attacker, leading to the disclosure of the client's identity and providing proof of possession of the client's private key.
Recommendation
Prioritize the upgrade of all applications utilizing the affected versions of urllib3.
- Upgrade to urllib3 2.8.0 or later to ensure proper isolation of proxy and target SSL contexts.
- Update codebases to use the
proxy_ssl_contextparameter for configuring TLS on HTTPS forwarding proxies rather than relying on global or target-specificssl_contextobjects. - Review applications using
use_forwarding_for_https=Trueto ensure they are not passing a sharedssl_contextthat may be mutated in-place during target-specific certificate verification. - Monitor for
FutureWarningmessages generated by urllib3 2.8.0, which indicate legacy configurations that will be deprecated and produce errors in urllib3 3.0.
Mitigations
Upgrade urllib3 to 2.8.0 or later across all environments
CVE-2026-97687