CPE
urllib3 versions 1.26.0 through 2.7.0 fail to properly isolate TLS configurations between HTTPS proxies and target servers, enabling potential man-in-the-middle attacks through certificate verification bypass or credential exposure.