Skip to content

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

High
sethmlarson published GHSA-5phf-pp7p-vc2r Mar 15, 2021

Package

pip urllib3 (pip)

Affected versions

>=1.26.0,<=1.26.3

Patched versions

>=1.26.4

Description

Impact

Users who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via proxy_config.
Only the default SSLContext is impacted.

Patches

urllib3 >=1.26.4 has the issue resolved. urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.

Workarounds

Upgrading is recommended as this is a minor release and not likely to break current usage.

Configuring an SSLContext with check_hostname=True and passing via proxy_config instead of relying on the default SSLContext

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-28363

Weaknesses

No CWEs

Credits