{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/urllib3--1.26.0--2.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:urllib3_project:urllib3:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-97687"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["urllib3 (\u003e= 1.26.0, \u003c 2.8.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Python library urllib3, in versions 1.26.0 through 2.7.0, contains a vulnerability (CVE-2026-97687) regarding the separation of TLS configurations for HTTPS proxies and target servers. The library incorrectly allows settings intended for the destination server - such as SNI, hostname assertions, certificate fingerprints, or client certificates - to be applied to the TLS handshake with the HTTPS proxy.\u003c/p\u003e\n\u003cp\u003eFurthermore, the library performs in-place mutation of SSL context objects when certificate verification is disabled for a target (e.g., using \u003ccode\u003ecert_reqs=\u0026quot;CERT_NONE\u0026quot;\u003c/code\u003e). Because this mutation is applied to the context object directly, these changes can persist and be applied to subsequent connections that reuse the same context, effectively disabling certificate verification for the proxy connection as well. An attacker capable of intercepting traffic to the HTTPS proxy can leverage these misconfigurations to impersonate the proxy, intercepting sensitive data, authentication tokens, or observing forwarded request bodies.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to perform man-in-the-middle attacks on HTTPS traffic forwarded through a proxy. This exposes sensitive information, including request/response bodies, credentials, and authentication tokens. Additionally, a client certificate intended for a target server might be improperly presented to the proxy or an attacker, leading to the disclosure of the client's identity and providing proof of possession of the client's private key.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all applications utilizing the affected versions of urllib3.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to urllib3 2.8.0 or later to ensure proper isolation of proxy and target SSL contexts.\u003c/li\u003e\n\u003cli\u003eUpdate codebases to use the \u003ccode\u003eproxy_ssl_context\u003c/code\u003e parameter for configuring TLS on HTTPS forwarding proxies rather than relying on global or target-specific \u003ccode\u003essl_context\u003c/code\u003e objects.\u003c/li\u003e\n\u003cli\u003eReview applications using \u003ccode\u003euse_forwarding_for_https=True\u003c/code\u003e to ensure they are not passing a shared \u003ccode\u003essl_context\u003c/code\u003e that may be mutated in-place during target-specific certificate verification.\u003c/li\u003e\n\u003cli\u003eMonitor for \u003ccode\u003eFutureWarning\u003c/code\u003e messages generated by urllib3 2.8.0, which indicate legacy configurations that will be deprecated and produce errors in urllib3 3.0.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T16:30:09Z","date_published":"2026-09-30T16:30:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-urllib3-tls-proxy-misconfiguration/","summary":"urllib3 versions 1.26.0 through 2.7.0 fail to properly isolate TLS configurations between HTTPS proxies and target servers, enabling potential man-in-the-middle attacks through certificate verification bypass or credential exposure.","title":"urllib3 HTTPS Proxy TLS Configuration Misisolation","url":"https://feed.craftedsignal.io/briefs/2026-09-urllib3-tls-proxy-misconfiguration/"}],"language":"en","title":"CraftedSignal Threat Feed - Urllib3 (\u003e= 1.26.0, \u003c 2.8.0)","version":"https://jsonfeed.org/version/1.1"}