CVE-2026-97687

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-440

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - urllib3 HTTPS Proxy TLS Context Confusion (CVE-2026-97687) In urllib3, target TLS options can bleed into the HTTPS proxy connection: using cert_reqs=CERT_NONE may mutate the proxy SSLContext so reused proxy connections skip cert verification. An on-path attacker impersonating the HTTPS proxy can MITM forwarded traffic or capture a target client cert. Direct HTTPS (no proxy) isn’t impacted. 👉Affected: urllib3 1.26.0-2.7.x

    0000041
    309 followersView on X

Explore more