highVulnerability

CVE-2026-97687

## Impact urllib3 supports configuring TLS independently for an HTTPS proxy and the target server. `proxy_ssl_context`, `proxy_assert_hostname`, and `proxy_assert_fingerprint` configure the TLS connection to the proxy. `ssl_context` and the other target-specific TLS parameters configure the connection to the target server. In urllib3 versions 1.26.0 through 2.7.0, these configurations were not consistently separated. Depending on the proxy mode, urllib3 could: 1. Ignore `proxy_ssl_context` and use the target server's SSL context for the TLS connection to an HTTPS forwarding proxy. 2. Override the HTTPS proxy's certificate-verification policy with the target server's certificate-verification policy. 3. Apply target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials to the TLS connection to an HTTPS forwarding proxy. In particular, configuring `cert_reqs="CERT_NONE"` for a target server could overwrite the `verify_mode` of the SSL context configured for the HTTPS proxy. This modification occurred in place and persisted on the context object, potentially disabling proxy certificate verification for later connections that reused the same context. An attacker able to intercept the connection to an HTTPS proxy may be able to impersonate the proxy when the effective proxy TLS configuration disables certificate verification or otherwise accepts the attacker's certificate. This may occur, for example, when the target server's trust or identity policy is incorrectly applied to the proxy connection. When HTTPS forwarding is enabled, an impersonated proxy can observe or modify forwarded requests and responses, potentially exposing credentials, authentication tokens, request bodies, response data, and other sensitive information. A TLS client certificate intended for the target server may also be presented to the proxy or to an attacker impersonating it. This can disclose the client's identity and provide proof of possession

Properties

ghsa_id
GHSA-8988-9cw3-xx77
summary
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
severity
high
last_source
GitHub Advisory Database
cve_id
CVE-2026-97687
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
false
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T14:46:04Z
source_url
https://github.com/advisories/GHSA-8988-9cw3-xx77
ghsa_updated
2026-09-30T14:46:05Z

Related Entities (5)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/urllib3

AFFECTS (1)

→[Software]pip/urllib3

HAS_WEAKNESS (2)

→[Weakness]Improper Certificate Validation
→[Weakness]Expected Behavior Violation

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-97687 — Ninja Signal Threat Intelligence | Ninja Signal