chore(deps): update dependency urllib3 to v2.8.0 #16

Open
renovate-bot wants to merge 1 commit from renovate/urllib3-2.x into master
Member

This PR contains the following updates:

Package Change Age Confidence
urllib3 (changelog) ==2.2.3 -> ==2.8.0 age confidence

Release Notes

urllib3/urllib3 (urllib3)

v2.8.0

Compare Source

==================

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden.
    (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size
    line of unbounded length in memory. (High severity,
    GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity,
    GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in
``proxy_ssl_context``, and proxy identity checks with
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option
    allowed_methods to retry any verb.
    (#&#8203;5044 <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience
    properties to the result of parse_url().
    (#&#8203;4945 <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to
    urllib3.util.make_headers().
    (#&#8203;5092 <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines
    (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF
    sequences from appearing in header values such as Set-Cookie.
    (#&#8203;1362 <https://github.com/urllib3/urllib3/issues/1362>__)

  • Fixed usage of proxy_ssl_context with ProxyManager when
    use_forwarding_for_https=True. Passing ssl_context instead of
    proxy_ssl_context for HTTPS proxies in this configuration now emits a
    FutureWarning and will raise an error in v3.0.
    (#&#8203;2577 <https://github.com/urllib3/urllib3/issues/2577>__)

  • Changed behavior of the default ConnectionPool.pool initialization.
    LifoQueue is now resolved from the queue module after the
    ConnectionPool is instantiated instead of using the default cached
    QueueCls class property. This is done because sometimes the
    queue.LifoQueue is monkey-patched late in the program, such as by gevent.
    (#&#8203;3289 <https://github.com/urllib3/urllib3/issues/3289>__)

  • Raised UnrewindableBodyError instead of ValueError when retrying a
    request whose body had tell() but not seek().
    (#&#8203;3779 <https://github.com/urllib3/urllib3/issues/3779>__)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with
    the proxy server.
    (#&#8203;3785 <https://github.com/urllib3/urllib3/issues/3785>__)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB
    chunks (same as the default amt when doing HTTPResponse.stream(...)).
    (#&#8203;5019 <https://github.com/urllib3/urllib3/issues/5019>__)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by
    socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and
    decimal integers (2130706433), ensuring SSL certificate verification uses
    the correct mode for these addresses.
    (#&#8203;5029 <https://github.com/urllib3/urllib3/issues/5029>__)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError
    instead of ValueError when called with an invalid timeout argument on
    a pool created with block=True.
    (#&#8203;5059 <https://github.com/urllib3/urllib3/issues/5059>__)

  • Fixed port-zero handling to preserve explicit :0 values instead of
    substituting the default ports 80 or 443 in URL parsing, pool selection,
    proxy configuration, connection_from_url(), and HTTP/2 request authority.
    (#&#8203;5071 <https://github.com/urllib3/urllib3/issues/5071>,
    #&#8203;5101 <https://github.com/urllib3/urllib3/issues/5101>
    )

  • Fixed a bug where PoolManager passed the assert_hostname and
    assert_fingerprint parameters to HTTP connection pools.
    (#&#8203;5077 <https://github.com/urllib3/urllib3/issues/5077>__)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL
    fragments from absolute request targets before sending requests.
    (#&#8203;5079 <https://github.com/urllib3/urllib3/issues/5079>__)

  • Added safeguards to the proxy tunneling code to prevent potential security
    issues when handling invalid characters in the proxy host and HTTP headers.
    This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
    the standard library does not contain the fix; those on newer Python versions
    should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
    (#&#8203;5091 <https://github.com/urllib3/urllib3/issues/5091>__)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's
    certificate policy and proxy identity checks with the target connection's TLS
    settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client
    credentials to forwarding proxy handshakes and continues to use its
    ssl_context as a fallback when an HTTPS proxy forwards an HTTP target.
    (#&#8203;5093 <https://github.com/urllib3/urllib3/issues/5093>__)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
    invalid host input such as raw spaces and control characters, malformed
    percent-encodings, and percent-encoded control characters in HTTP(S) hosts
    and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
    normalization now also follows RFC 3986 normalization rules for
    percent-encoded octets by decoding percent-encoded unreserved characters and
    uppercasing the hexadecimal digits of retained percent-encoded octets.
    (#&#8203;5095 <https://github.com/urllib3/urllib3/issues/5095>__)

  • Fixed an AttributeError on Python built with OpenSSL 4+, where
    ssl.PROTOCOL_TLSv1 no longer exists.
    (#&#8203;5097 <https://github.com/urllib3/urllib3/issues/5097>__)

  • Fixed urllib3.contrib.pyopenssl to use cryptography APIs when reading a
    certificate subject and loading encrypted private keys, avoiding
    DeprecationWarning raised by pyOpenSSL 26.3.0+.
    (#&#8203;5103 <https://github.com/urllib3/urllib3/issues/5103>__)

  • Fixed handling of HTTP 303 redirects for requests with chunked or file-like
    bodies.
    (#&#8203;5161 <https://github.com/urllib3/urllib3/issues/5161>__)

  • Fixed assert_fingerprint() to raise SSLError instead of
    binascii.Error when a fingerprint has a supported length but contains
    non-hexadecimal characters.
    (#&#8203;5211 <https://github.com/urllib3/urllib3/issues/5211>__)

Misc

  • Added a test dependency group containing the minimum dependencies needed
    to run the test suite, intended for downstream packagers. The dev-base
    and mypy groups now include this new group via include-group,
    removing duplication.
    (#&#8203;3594 <https://github.com/urllib3/urllib3/issues/3594>__)
  • Fixed test failures with pytest >= 9.1.
    (#&#8203;5094 <https://github.com/urllib3/urllib3/issues/5094>__)
  • Enabled JSPI tests with Firefox in the Emscripten test suite.
    (#&#8203;5166 <https://github.com/urllib3/urllib3/issues/5166>__)
  • Improved streamed response decoding performance.
    (#&#8203;5209 <https://github.com/urllib3/urllib3/issues/5209>__)
  • Fixed flaky tests.
    (#&#8203;5232 <https://github.com/urllib3/urllib3/issues/5232>,
    #&#8203;5234 <https://github.com/urllib3/urllib3/issues/5234>
    ,
    #&#8203;5239 <https://github.com/urllib3/urllib3/issues/5239>__)

v2.7.0

Compare Source

=======================

Security

Addressed high-severity security issues.
Impact was limited to specific use cases detailed in the accompanying
advisories; overall user exposure was estimated to be marginal.

  • Decompression-bomb safeguards of the streaming API were bypassed:

    1. When HTTPResponse.drain_conn() was called after the response had been
      read and decompressed partially.
    2. During the second HTTPResponse.read(amt=N) or
      HTTPResponse.stream(amt=N) call when the response was decompressed
      using the official Brotli <https://pypi.org/project/brotli/>__ library.

    See GHSA-mf9v-mfxr-j63j <https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j>__
    for details.

  • HTTP pools created using ProxyManager.connection_from_url did not strip
    sensitive headers specified in Retry.remove_headers_on_redirect when
    redirecting to a different host.
    (GHSA-qccp-gfcp-xxvc <https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc>__)

Deprecations and Removals

  • Used FutureWarning instead of DeprecationWarning for better
    visibility of existing deprecation notices. Rescheduled the removal of
    deprecated features to version 3.0.
    (#&#8203;3763 <https://github.com/urllib3/urllib3/issues/3763>__)
  • Removed support for end-of-life Python 3.9.
    (#&#8203;3720 <https://github.com/urllib3/urllib3/issues/3720>__)
  • Removed support for end-of-life PyPy3.10.
    (#&#8203;4979 <https://github.com/urllib3/urllib3/issues/4979>__)
  • Bumped the minimum supported pyOpenSSL version to 19.0.0.
    (#&#8203;3777 <https://github.com/urllib3/urllib3/issues/3777>__)

Bugfixes

  • Fixed a bug where HTTPResponse.read(amt=None) was ignoring decompressed
    data buffered from previous partial reads.
    (#&#8203;3636 <https://github.com/urllib3/urllib3/issues/3636>__)
  • Fixed a bug where HTTPResponse.read() could cache only part of the
    response after a partial read when cache_content=True.
    (#&#8203;4967 <https://github.com/urllib3/urllib3/issues/4967>__)
  • Fixed HTTPResponse.stream() and HTTPResponse.read_chunked() to handle
    amt=0.
    (#&#8203;3793 <https://github.com/urllib3/urllib3/issues/3793>__)
  • Updated _TYPE_BODY type alias to include missing Iterable[str],
    matching the documented and runtime behavior of chunked request bodies.
    (#&#8203;3798 <https://github.com/urllib3/urllib3/issues/3798>__)
  • Fixed LocationParseError when paths resembling schemeless URIs were
    passed to HTTPConnectionPool.urlopen().
    (#&#8203;3352 <https://github.com/urllib3/urllib3/issues/3352>__)
  • Fixed BaseHTTPResponse.readinto() type annotation to accept
    memoryview in addition to bytearray, matching the
    io.RawIOBase.readinto contract and enabling use with
    io.BufferedReader without type errors.
    (#&#8203;3764 <https://github.com/urllib3/urllib3/issues/3764>__)

v2.6.3

Compare Source

==================

  • Fixed a high-severity security issue where decompression-bomb safeguards of
    the streaming API were bypassed when HTTP redirects were followed.
    (GHSA-38jv-5279-wg99 <https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99>__)
  • Started treating Retry-After times greater than 6 hours as 6 hours by
    default. (#&#8203;3743 <https://github.com/urllib3/urllib3/issues/3743>__)
  • Fixed urllib3.connection.VerifiedHTTPSConnection on Emscripten.
    (#&#8203;3752 <https://github.com/urllib3/urllib3/issues/3752>__)

v2.6.2

Compare Source

==================

  • Fixed HTTPResponse.read_chunked() to properly handle leftover data in
    the decoder's buffer when reading compressed chunked responses.
    (#&#8203;3734 <https://github.com/urllib3/urllib3/issues/3734>__)

v2.6.1

Compare Source

==================

  • Restore previously removed HTTPResponse.getheaders() and
    HTTPResponse.getheader() methods.
    (#&#8203;3731 <https://github.com/urllib3/urllib3/issues/3731>__)

v2.6.0

Compare Source

==================

Security

  • Fixed a security issue where streaming API could improperly handle highly
    compressed HTTP content ("decompression bombs") leading to excessive resource
    consumption even when a small amount of data was requested. Reading small
    chunks of compressed data is safer and much more efficient now.
    (GHSA-2xpw-w6gg-jr37 <https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37>__)
  • Fixed a security issue where an attacker could compose an HTTP response with
    virtually unlimited links in the Content-Encoding header, potentially
    leading to a denial of service (DoS) attack by exhausting system resources
    during decoding. The number of allowed chained encodings is now limited to 5.
    (GHSA-gm62-xv2j-4w53 <https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53>__)

.. caution::

  • If urllib3 is not installed with the optional urllib3[brotli] extra, but
    your environment contains a Brotli/brotlicffi/brotlipy package anyway, make
    sure to upgrade it to at least Brotli 1.2.0 or brotlicffi 1.2.0.0 to
    benefit from the security fixes and avoid warnings. Prefer using
    urllib3[brotli] to install a compatible Brotli package automatically.

  • If you use custom decompressors, please make sure to update them to
    respect the changed API of urllib3.response.ContentDecoder.

Features

  • Enabled retrieval, deletion, and membership testing in HTTPHeaderDict using bytes keys. (#&#8203;3653 <https://github.com/urllib3/urllib3/issues/3653>__)
  • Added host and port information to string representations of HTTPConnection. (#&#8203;3666 <https://github.com/urllib3/urllib3/issues/3666>__)
  • Added support for Python 3.14 free-threading builds explicitly. (#&#8203;3696 <https://github.com/urllib3/urllib3/issues/3696>__)

Removals

  • Removed the HTTPResponse.getheaders() method in favor of HTTPResponse.headers.
    Removed the HTTPResponse.getheader(name, default) method in favor of HTTPResponse.headers.get(name, default). (#&#8203;3622 <https://github.com/urllib3/urllib3/issues/3622>__)

Bugfixes

  • Fixed redirect handling in urllib3.PoolManager when an integer is passed
    for the retries parameter. (#&#8203;3649 <https://github.com/urllib3/urllib3/issues/3649>__)
  • Fixed HTTPConnectionPool when used in Emscripten with no explicit port. (#&#8203;3664 <https://github.com/urllib3/urllib3/issues/3664>__)
  • Fixed handling of SSLKEYLOGFILE with expandable variables. (#&#8203;3700 <https://github.com/urllib3/urllib3/issues/3700>__)

Misc

  • Changed the zstd extra to install backports.zstd instead of zstandard on Python 3.13 and before. (#&#8203;3693 <https://github.com/urllib3/urllib3/issues/3693>__)
  • Improved the performance of content decoding by optimizing BytesQueueBuffer class. (#&#8203;3710 <https://github.com/urllib3/urllib3/issues/3710>__)
  • Allowed building the urllib3 package with newer setuptools-scm v9.x. (#&#8203;3652 <https://github.com/urllib3/urllib3/issues/3652>__)
  • Ensured successful urllib3 builds by setting Hatchling requirement to >= 1.27.0. (#&#8203;3638 <https://github.com/urllib3/urllib3/issues/3638>__)

v2.5.0

Compare Source

==================

Features

  • Added support for the compression.zstd module that is new in Python 3.14.
    See PEP 784 <https://peps.python.org/pep-0784/>_ for more information. (#&#8203;3610 <https://github.com/urllib3/urllib3/issues/3610>__)
  • Added support for version 0.5 of hatch-vcs (#&#8203;3612 <https://github.com/urllib3/urllib3/issues/3612>__)

Bugfixes

  • Fixed a security issue where restricting the maximum number of followed
    redirects at the urllib3.PoolManager level via the retries parameter
    did not work.
  • Made the Node.js runtime respect redirect parameters such as retries
    and redirects.
  • Raised exception for HTTPResponse.shutdown on a connection already released to the pool. (#&#8203;3581 <https://github.com/urllib3/urllib3/issues/3581>__)
  • Fixed incorrect CONNECT statement when using an IPv6 proxy with connection_from_host. Previously would not be wrapped in []. (#&#8203;3615 <https://github.com/urllib3/urllib3/issues/3615>__)

v2.4.0

Compare Source

==================

Features

  • Applied PEP 639 by specifying the license fields in pyproject.toml. (#&#8203;3522 <https://github.com/urllib3/urllib3/issues/3522>__)
  • Updated exceptions to save and restore more properties during the pickle/serialization process. (#&#8203;3567 <https://github.com/urllib3/urllib3/issues/3567>__)
  • Added verify_flags option to create_urllib3_context with a default of VERIFY_X509_PARTIAL_CHAIN and VERIFY_X509_STRICT for Python 3.13+. (#&#8203;3571 <https://github.com/urllib3/urllib3/issues/3571>__)

Bugfixes

  • Fixed a bug with partial reads of streaming data in Emscripten. (#&#8203;3555 <https://github.com/urllib3/urllib3/issues/3555>__)

Misc

  • Switched to uv for installing development dependecies. (#&#8203;3550 <https://github.com/urllib3/urllib3/issues/3550>__)
  • Removed the multiple.intoto.jsonl asset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. (#&#8203;3566 <https://github.com/urllib3/urllib3/issues/3566>__)

v2.3.0

Compare Source

==================

Features

  • Applied PEP 639 by specifying the license fields in pyproject.toml. (#&#8203;3522 <https://github.com/urllib3/urllib3/issues/3522>__)
  • Updated exceptions to save and restore more properties during the pickle/serialization process. (#&#8203;3567 <https://github.com/urllib3/urllib3/issues/3567>__)
  • Added verify_flags option to create_urllib3_context with a default of VERIFY_X509_PARTIAL_CHAIN and VERIFY_X509_STRICT for Python 3.13+. (#&#8203;3571 <https://github.com/urllib3/urllib3/issues/3571>__)

Bugfixes

  • Fixed a bug with partial reads of streaming data in Emscripten. (#&#8203;3555 <https://github.com/urllib3/urllib3/issues/3555>__)

Misc

  • Switched to uv for installing development dependecies. (#&#8203;3550 <https://github.com/urllib3/urllib3/issues/3550>__)
  • Removed the multiple.intoto.jsonl asset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. (#&#8203;3566 <https://github.com/urllib3/urllib3/issues/3566>__)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [urllib3](https://github.com/urllib3/urllib3) ([changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)) | `==2.2.3` -> `==2.8.0` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/urllib3/2.8.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/urllib3/2.2.3/2.8.0?slim=true) | --- ### Release Notes <details> <summary>urllib3/urllib3 (urllib3)</summary> ### [`v2.8.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#280-2026-09-15) [Compare Source](https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0) \================== ## Security Fixed the following security issues: - The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, `GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`\_\_) - `HTTPResponse.stream()` and `read_chunked()` could buffer a chunk-size line of unbounded length in memory. (High severity, `GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`\_\_) - Chunked Deflate streaming could enter an infinite loop. (Medium severity, `GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`\_\_) .. caution:: ``` urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. Configure proxy CA certificates and client certificates in ``proxy_ssl_context``, and proxy identity checks with ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. ``` ## Deprecations & Removals - Deprecated using an empty collection as the `Retry` option `allowed_methods` to retry any verb. (`#&#8203;5044 <https://github.com/urllib3/urllib3/issues/5044>`\_\_) ## Features - Added `Url.auth_decoded` and `Url.auth_decoded_joined` convenience properties to the result of `parse_url()`. (`#&#8203;4945 <https://github.com/urllib3/urllib3/issues/4945>`\_\_) - Added `basic_auth_encoding` and `proxy_basic_auth_encoding` parameters to `urllib3.util.make_headers()`. (`#&#8203;5092 <https://github.com/urllib3/urllib3/issues/5092>`\_\_) ## Bugfixes - Fixed response header handling to replace obsolete folded header lines (`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as `Set-Cookie`. (`#&#8203;1362 <https://github.com/urllib3/urllib3/issues/1362>`\_\_) - Fixed usage of `proxy_ssl_context` with `ProxyManager` when `use_forwarding_for_https=True`. Passing `ssl_context` instead of `proxy_ssl_context` for HTTPS proxies in this configuration now emits a `FutureWarning` and will raise an error in v3.0. (`#&#8203;2577 <https://github.com/urllib3/urllib3/issues/2577>`\_\_) - Changed behavior of the default `ConnectionPool.pool` initialization. `LifoQueue` is now resolved from the `queue` module after the `ConnectionPool` is instantiated instead of using the default cached `QueueCls` class property. This is done because sometimes the `queue.LifoQueue` is monkey-patched late in the program, such as by gevent. (`#&#8203;3289 <https://github.com/urllib3/urllib3/issues/3289>`\_\_) - Raised `UnrewindableBodyError` instead of `ValueError` when retrying a request whose body had `tell()` but not `seek()`. (`#&#8203;3779 <https://github.com/urllib3/urllib3/issues/3779>`\_\_) - Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (`#&#8203;3785 <https://github.com/urllib3/urllib3/issues/3785>`\_\_) - Fixed `HTTPResponse.drain_conn()` to discard unread response data in 64 KiB chunks (same as the default `amt` when doing `HTTPResponse.stream(...)`). (`#&#8203;5019 <https://github.com/urllib3/urllib3/issues/5019>`\_\_) - Fixed `is_ipaddress()` to detect non-standard IPv4 forms accepted by `socket.connect`, such as hex (`0x7f000001`), octal (`0177.0.0.1`), and decimal integers (`2130706433`), ensuring SSL certificate verification uses the correct mode for these addresses. (`#&#8203;5029 <https://github.com/urllib3/urllib3/issues/5029>`\_\_) - Fixed `HTTPConnectionPool.urlopen` raising a misleading `FullPoolError` instead of `ValueError` when called with an invalid `timeout` argument on a pool created with `block=True`. (`#&#8203;5059 <https://github.com/urllib3/urllib3/issues/5059>`\_\_) - Fixed port-zero handling to preserve explicit `:0` values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, `connection_from_url()`, and HTTP/2 request authority. (`#&#8203;5071 <https://github.com/urllib3/urllib3/issues/5071>`**, `#&#8203;5101 <https://github.com/urllib3/urllib3/issues/5101>`**) - Fixed a bug where `PoolManager` passed the `assert_hostname` and `assert_fingerprint` parameters to HTTP connection pools. (`#&#8203;5077 <https://github.com/urllib3/urllib3/issues/5077>`\_\_) - Fixed `HTTPConnectionPool.urlopen()` and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (`#&#8203;5079 <https://github.com/urllib3/urllib3/issues/5079>`\_\_) - Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (`#&#8203;5091 <https://github.com/urllib3/urllib3/issues/5091>`\_\_) - Fixed `HTTPSConnection.connect()` overriding `ProxyConfig.ssl_context`'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy. `HTTPSConnection` no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its `ssl_context` as a fallback when an HTTPS proxy forwards an HTTP target. (`#&#8203;5093 <https://github.com/urllib3/urllib3/issues/5093>`\_\_) - Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (`#&#8203;5095 <https://github.com/urllib3/urllib3/issues/5095>`\_\_) - Fixed an `AttributeError` on Python built with OpenSSL 4+, where `ssl.PROTOCOL_TLSv1` no longer exists. (`#&#8203;5097 <https://github.com/urllib3/urllib3/issues/5097>`\_\_) - Fixed `urllib3.contrib.pyopenssl` to use cryptography APIs when reading a certificate subject and loading encrypted private keys, avoiding `DeprecationWarning` raised by pyOpenSSL 26.3.0+. (`#&#8203;5103 <https://github.com/urllib3/urllib3/issues/5103>`\_\_) - Fixed handling of HTTP 303 redirects for requests with chunked or file-like bodies. (`#&#8203;5161 <https://github.com/urllib3/urllib3/issues/5161>`\_\_) - Fixed `assert_fingerprint()` to raise `SSLError` instead of `binascii.Error` when a fingerprint has a supported length but contains non-hexadecimal characters. (`#&#8203;5211 <https://github.com/urllib3/urllib3/issues/5211>`\_\_) ## Misc - Added a `test` dependency group containing the minimum dependencies needed to run the test suite, intended for downstream packagers. The `dev-base` and `mypy` groups now include this new group via `include-group`, removing duplication. (`#&#8203;3594 <https://github.com/urllib3/urllib3/issues/3594>`\_\_) - Fixed test failures with pytest >= 9.1. (`#&#8203;5094 <https://github.com/urllib3/urllib3/issues/5094>`\_\_) - Enabled JSPI tests with Firefox in the Emscripten test suite. (`#&#8203;5166 <https://github.com/urllib3/urllib3/issues/5166>`\_\_) - Improved streamed response decoding performance. (`#&#8203;5209 <https://github.com/urllib3/urllib3/issues/5209>`\_\_) - Fixed flaky tests. (`#&#8203;5232 <https://github.com/urllib3/urllib3/issues/5232>`**, `#&#8203;5234 <https://github.com/urllib3/urllib3/issues/5234>`**, `#&#8203;5239 <https://github.com/urllib3/urllib3/issues/5239>`\_\_) ### [`v2.7.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#270-2026-05-07) [Compare Source](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0) \======================= ## Security Addressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal. - Decompression-bomb safeguards of the streaming API were bypassed: 1. When `HTTPResponse.drain_conn()` was called after the response had been read and decompressed partially. 2. During the second `HTTPResponse.read(amt=N)` or `HTTPResponse.stream(amt=N)` call when the response was decompressed using the official `Brotli <https://pypi.org/project/brotli/>`\_\_ library. See `GHSA-mf9v-mfxr-j63j <https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j>`\_\_ for details. - HTTP pools created using `ProxyManager.connection_from_url` did not strip sensitive headers specified in `Retry.remove_headers_on_redirect` when redirecting to a different host. (`GHSA-qccp-gfcp-xxvc <https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc>`\_\_) ## Deprecations and Removals - Used `FutureWarning` instead of `DeprecationWarning` for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (`#&#8203;3763 <https://github.com/urllib3/urllib3/issues/3763>`\_\_) - Removed support for end-of-life Python 3.9. (`#&#8203;3720 <https://github.com/urllib3/urllib3/issues/3720>`\_\_) - Removed support for end-of-life PyPy3.10. (`#&#8203;4979 <https://github.com/urllib3/urllib3/issues/4979>`\_\_) - Bumped the minimum supported pyOpenSSL version to 19.0.0. (`#&#8203;3777 <https://github.com/urllib3/urllib3/issues/3777>`\_\_) ## Bugfixes - Fixed a bug where `HTTPResponse.read(amt=None)` was ignoring decompressed data buffered from previous partial reads. (`#&#8203;3636 <https://github.com/urllib3/urllib3/issues/3636>`\_\_) - Fixed a bug where `HTTPResponse.read()` could cache only part of the response after a partial read when `cache_content=True`. (`#&#8203;4967 <https://github.com/urllib3/urllib3/issues/4967>`\_\_) - Fixed `HTTPResponse.stream()` and `HTTPResponse.read_chunked()` to handle `amt=0`. (`#&#8203;3793 <https://github.com/urllib3/urllib3/issues/3793>`\_\_) - Updated `_TYPE_BODY` type alias to include missing `Iterable[str]`, matching the documented and runtime behavior of chunked request bodies. (`#&#8203;3798 <https://github.com/urllib3/urllib3/issues/3798>`\_\_) - Fixed `LocationParseError` when paths resembling schemeless URIs were passed to `HTTPConnectionPool.urlopen()`. (`#&#8203;3352 <https://github.com/urllib3/urllib3/issues/3352>`\_\_) - Fixed `BaseHTTPResponse.readinto()` type annotation to accept `memoryview` in addition to `bytearray`, matching the `io.RawIOBase.readinto` contract and enabling use with `io.BufferedReader` without type errors. (`#&#8203;3764 <https://github.com/urllib3/urllib3/issues/3764>`\_\_) ### [`v2.6.3`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#263-2026-01-07) [Compare Source](https://github.com/urllib3/urllib3/compare/2.6.2...2.6.3) \================== - Fixed a high-severity security issue where decompression-bomb safeguards of the streaming API were bypassed when HTTP redirects were followed. (`GHSA-38jv-5279-wg99 <https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99>`\_\_) - Started treating `Retry-After` times greater than 6 hours as 6 hours by default. (`#&#8203;3743 <https://github.com/urllib3/urllib3/issues/3743>`\_\_) - Fixed `urllib3.connection.VerifiedHTTPSConnection` on Emscripten. (`#&#8203;3752 <https://github.com/urllib3/urllib3/issues/3752>`\_\_) ### [`v2.6.2`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#262-2025-12-11) [Compare Source](https://github.com/urllib3/urllib3/compare/2.6.1...2.6.2) \================== - Fixed `HTTPResponse.read_chunked()` to properly handle leftover data in the decoder's buffer when reading compressed chunked responses. (`#&#8203;3734 <https://github.com/urllib3/urllib3/issues/3734>`\_\_) ### [`v2.6.1`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#261-2025-12-08) [Compare Source](https://github.com/urllib3/urllib3/compare/2.6.0...2.6.1) \================== - Restore previously removed `HTTPResponse.getheaders()` and `HTTPResponse.getheader()` methods. (`#&#8203;3731 <https://github.com/urllib3/urllib3/issues/3731>`\_\_) ### [`v2.6.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#260-2025-12-05) [Compare Source](https://github.com/urllib3/urllib3/compare/2.5.0...2.6.0) \================== ## Security - Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small chunks of compressed data is safer and much more efficient now. (`GHSA-2xpw-w6gg-jr37 <https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37>`\_\_) - Fixed a security issue where an attacker could compose an HTTP response with virtually unlimited links in the `Content-Encoding` header, potentially leading to a denial of service (DoS) attack by exhausting system resources during decoding. The number of allowed chained encodings is now limited to 5. (`GHSA-gm62-xv2j-4w53 <https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53>`\_\_) .. caution:: - If urllib3 is not installed with the optional `urllib3[brotli]` extra, but your environment contains a Brotli/brotlicffi/brotlipy package anyway, make sure to upgrade it to at least Brotli 1.2.0 or brotlicffi 1.2.0.0 to benefit from the security fixes and avoid warnings. Prefer using `urllib3[brotli]` to install a compatible Brotli package automatically. - If you use custom decompressors, please make sure to update them to respect the changed API of `urllib3.response.ContentDecoder`. ## Features - Enabled retrieval, deletion, and membership testing in `HTTPHeaderDict` using bytes keys. (`#&#8203;3653 <https://github.com/urllib3/urllib3/issues/3653>`\_\_) - Added host and port information to string representations of `HTTPConnection`. (`#&#8203;3666 <https://github.com/urllib3/urllib3/issues/3666>`\_\_) - Added support for Python 3.14 free-threading builds explicitly. (`#&#8203;3696 <https://github.com/urllib3/urllib3/issues/3696>`\_\_) ## Removals - Removed the `HTTPResponse.getheaders()` method in favor of `HTTPResponse.headers`. Removed the `HTTPResponse.getheader(name, default)` method in favor of `HTTPResponse.headers.get(name, default)`. (`#&#8203;3622 <https://github.com/urllib3/urllib3/issues/3622>`\_\_) ## Bugfixes - Fixed redirect handling in `urllib3.PoolManager` when an integer is passed for the retries parameter. (`#&#8203;3649 <https://github.com/urllib3/urllib3/issues/3649>`\_\_) - Fixed `HTTPConnectionPool` when used in Emscripten with no explicit port. (`#&#8203;3664 <https://github.com/urllib3/urllib3/issues/3664>`\_\_) - Fixed handling of `SSLKEYLOGFILE` with expandable variables. (`#&#8203;3700 <https://github.com/urllib3/urllib3/issues/3700>`\_\_) ## Misc - Changed the `zstd` extra to install `backports.zstd` instead of `zstandard` on Python 3.13 and before. (`#&#8203;3693 <https://github.com/urllib3/urllib3/issues/3693>`\_\_) - Improved the performance of content decoding by optimizing `BytesQueueBuffer` class. (`#&#8203;3710 <https://github.com/urllib3/urllib3/issues/3710>`\_\_) - Allowed building the urllib3 package with newer setuptools-scm v9.x. (`#&#8203;3652 <https://github.com/urllib3/urllib3/issues/3652>`\_\_) - Ensured successful urllib3 builds by setting Hatchling requirement to >= 1.27.0. (`#&#8203;3638 <https://github.com/urllib3/urllib3/issues/3638>`\_\_) ### [`v2.5.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#250-2025-06-18) [Compare Source](https://github.com/urllib3/urllib3/compare/2.4.0...2.5.0) \================== ## Features - Added support for the `compression.zstd` module that is new in Python 3.14. See `PEP 784 <https://peps.python.org/pep-0784/>`\_ for more information. (`#&#8203;3610 <https://github.com/urllib3/urllib3/issues/3610>`\_\_) - Added support for version 0.5 of `hatch-vcs` (`#&#8203;3612 <https://github.com/urllib3/urllib3/issues/3612>`\_\_) ## Bugfixes - Fixed a security issue where restricting the maximum number of followed redirects at the `urllib3.PoolManager` level via the `retries` parameter did not work. - Made the Node.js runtime respect redirect parameters such as `retries` and `redirects`. - Raised exception for `HTTPResponse.shutdown` on a connection already released to the pool. (`#&#8203;3581 <https://github.com/urllib3/urllib3/issues/3581>`\_\_) - Fixed incorrect `CONNECT` statement when using an IPv6 proxy with `connection_from_host`. Previously would not be wrapped in `[]`. (`#&#8203;3615 <https://github.com/urllib3/urllib3/issues/3615>`\_\_) ### [`v2.4.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#240-2025-04-10) [Compare Source](https://github.com/urllib3/urllib3/compare/2.3.0...2.4.0) \================== ## Features - Applied PEP 639 by specifying the license fields in pyproject.toml. (`#&#8203;3522 <https://github.com/urllib3/urllib3/issues/3522>`\_\_) - Updated exceptions to save and restore more properties during the pickle/serialization process. (`#&#8203;3567 <https://github.com/urllib3/urllib3/issues/3567>`\_\_) - Added `verify_flags` option to `create_urllib3_context` with a default of `VERIFY_X509_PARTIAL_CHAIN` and `VERIFY_X509_STRICT` for Python 3.13+. (`#&#8203;3571 <https://github.com/urllib3/urllib3/issues/3571>`\_\_) ## Bugfixes - Fixed a bug with partial reads of streaming data in Emscripten. (`#&#8203;3555 <https://github.com/urllib3/urllib3/issues/3555>`\_\_) ## Misc - Switched to uv for installing development dependecies. (`#&#8203;3550 <https://github.com/urllib3/urllib3/issues/3550>`\_\_) - Removed the `multiple.intoto.jsonl` asset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. (`#&#8203;3566 <https://github.com/urllib3/urllib3/issues/3566>`\_\_) ### [`v2.3.0`](https://github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#240-2025-04-10) [Compare Source](https://github.com/urllib3/urllib3/compare/2.2.3...2.3.0) \================== ## Features - Applied PEP 639 by specifying the license fields in pyproject.toml. (`#&#8203;3522 <https://github.com/urllib3/urllib3/issues/3522>`\_\_) - Updated exceptions to save and restore more properties during the pickle/serialization process. (`#&#8203;3567 <https://github.com/urllib3/urllib3/issues/3567>`\_\_) - Added `verify_flags` option to `create_urllib3_context` with a default of `VERIFY_X509_PARTIAL_CHAIN` and `VERIFY_X509_STRICT` for Python 3.13+. (`#&#8203;3571 <https://github.com/urllib3/urllib3/issues/3571>`\_\_) ## Bugfixes - Fixed a bug with partial reads of streaming data in Emscripten. (`#&#8203;3555 <https://github.com/urllib3/urllib3/issues/3555>`\_\_) ## Misc - Switched to uv for installing development dependecies. (`#&#8203;3550 <https://github.com/urllib3/urllib3/issues/3550>`\_\_) - Removed the `multiple.intoto.jsonl` asset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. (`#&#8203;3566 <https://github.com/urllib3/urllib3/issues/3566>`\_\_) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Mi4yIiwidXBkYXRlZEluVmVyIjoiNDIuNTIuOCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJyZW5vdmF0ZS1ib3QiXX0=-->
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.3.0 to chore(deps): update dependency urllib3 to v2.4.0 2025-04-14 05:16:36 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from feeca22ea7 to c4ff937604 2025-04-14 05:16:38 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.4.0 to chore(deps): update dependency urllib3 to v2.5.0 2025-06-23 05:26:07 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from c4ff937604 to 81fe606448 2025-06-23 05:26:08 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.5.0 to chore(deps): update dependency urllib3 to v2.6.0 2025-12-08 05:20:32 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from 81fe606448 to 21a8f28122 2025-12-08 05:20:34 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.6.0 to chore(deps): update dependency urllib3 to v2.6.2 2025-12-15 05:20:31 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from 21a8f28122 to 6b743a0741 2025-12-15 05:20:31 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.6.2 to chore(deps): update dependency urllib3 to v2.6.3 2026-01-12 05:18:09 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from 6b743a0741 to 499c88d09d 2026-01-12 05:18:11 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.6.3 to chore(deps): update dependency urllib3 to v2.7.0 2026-05-11 05:18:54 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from 499c88d09d to b27e3766de 2026-05-11 05:18:55 +05:30 Compare
renovate-bot force-pushed renovate/urllib3-2.x from b27e3766de to 5ce4ab39aa 2026-06-15 15:35:04 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency urllib3 to v2.7.0 to chore(deps): update dependency urllib3 to v2.8.0 2026-09-21 05:15:53 +05:30
renovate-bot force-pushed renovate/urllib3-2.x from 5ce4ab39aa to 2b4d07439e 2026-09-21 05:15:55 +05:30 Compare
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/urllib3-2.x:renovate/urllib3-2.x
git switch renovate/urllib3-2.x

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch master
git merge --no-ff renovate/urllib3-2.x
git switch renovate/urllib3-2.x
git rebase master
git switch master
git merge --ff-only renovate/urllib3-2.x
git switch renovate/urllib3-2.x
git rebase master
git switch master
git merge --no-ff renovate/urllib3-2.x
git switch master
git merge --squash renovate/urllib3-2.x
git switch master
git merge --ff-only renovate/urllib3-2.x
git switch master
git merge renovate/urllib3-2.x
git push origin master
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mCaptcha/mcaptcha-api-rs!16
No description provided.