<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:urllib3_project:urllib3:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aurllib3_projecturllib3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:30:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aurllib3_projecturllib3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>urllib3 HTTPS Proxy TLS Configuration Misisolation</title><link>https://feed.craftedsignal.io/briefs/2026-09-urllib3-tls-proxy-misconfiguration/</link><pubDate>Wed, 30 Sep 2026 16:30:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-urllib3-tls-proxy-misconfiguration/</guid><description>urllib3 versions 1.26.0 through 2.7.0 fail to properly isolate TLS configurations between HTTPS proxies and target servers, enabling potential man-in-the-middle attacks through certificate verification bypass or credential exposure.</description><content:encoded><![CDATA[<p>The Python library urllib3, in versions 1.26.0 through 2.7.0, contains a vulnerability (CVE-2026-97687) regarding the separation of TLS configurations for HTTPS proxies and target servers. The library incorrectly allows settings intended for the destination server - such as SNI, hostname assertions, certificate fingerprints, or client certificates - to be applied to the TLS handshake with the HTTPS proxy.</p>
<p>Furthermore, the library performs in-place mutation of SSL context objects when certificate verification is disabled for a target (e.g., using <code>cert_reqs=&quot;CERT_NONE&quot;</code>). Because this mutation is applied to the context object directly, these changes can persist and be applied to subsequent connections that reuse the same context, effectively disabling certificate verification for the proxy connection as well. An attacker capable of intercepting traffic to the HTTPS proxy can leverage these misconfigurations to impersonate the proxy, intercepting sensitive data, authentication tokens, or observing forwarded request bodies.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to perform man-in-the-middle attacks on HTTPS traffic forwarded through a proxy. This exposes sensitive information, including request/response bodies, credentials, and authentication tokens. Additionally, a client certificate intended for a target server might be improperly presented to the proxy or an attacker, leading to the disclosure of the client's identity and providing proof of possession of the client's private key.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of all applications utilizing the affected versions of urllib3.</p>
<ul>
<li>Upgrade to urllib3 2.8.0 or later to ensure proper isolation of proxy and target SSL contexts.</li>
<li>Update codebases to use the <code>proxy_ssl_context</code> parameter for configuring TLS on HTTPS forwarding proxies rather than relying on global or target-specific <code>ssl_context</code> objects.</li>
<li>Review applications using <code>use_forwarding_for_https=True</code> to ensure they are not passing a shared <code>ssl_context</code> that may be mutated in-place during target-specific certificate verification.</li>
<li>Monitor for <code>FutureWarning</code> messages generated by urllib3 2.8.0, which indicate legacy configurations that will be deprecated and produce errors in urllib3 3.0.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>