urllib3 2.7.0

2.7.0
Changed 2
  • Used FutureWarning instead of DeprecationWarning for better visibility of deprecation notices
  • Bumped minimum supported pyOpenSSL version to 19.0.0
Fixed 6
  • Fixed HTTPResponse.read(amt=None) ignoring decompressed data buffered from previous partial reads
  • Fixed HTTPResponse.read() caching only part of response after partial read when cache_content=True
  • Fixed HTTPResponse.stream() and HTTPResponse.read_chunked() to handle amt=0
  • Updated _TYPE_BODY type alias to include missing Iterable[str] for chunked request bodies
  • Fixed LocationParseError when paths resembling schemeless URIs were passed to HTTPConnectionPool.urlopen()
  • Fixed BaseHTTPResponse.readinto() type annotation to accept memoryview in addition to bytearray
Removed 2
  • Removed support for end-of-life Python 3.9
  • Removed support for end-of-life PyPy3.10
Security 3
  • Fixed decompression-bomb safeguards bypass when HTTPResponse.drain_conn() was called after partial decompression
  • Fixed decompression-bomb safeguards bypass during second HTTPResponse.read(amt=N) or HTTPResponse.stream(amt=N) call with Brotli decompression
  • Fixed HTTP pools created using ProxyManager.connection_from_url to strip sensitive headers specified in Retry.remove_headers_on_redirect when redirecting to a different host
🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Addressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.

  • Decompression-bomb safeguards of the streaming API were bypassed:

    1. When HTTPResponse.drain_conn() was called after the response had been read and decompressed partially. (Reported by @Cycloctane)
    2. During the second HTTPResponse.read(amt=N) or HTTPResponse.stream(amt=N) call when the response was decompressed using the official Brotli library. (Reported by @kimkou2024)

    See GHSA-mf9v-mfxr-j63j for details.

  • HTTP pools created using ProxyManager.connection_from_url did not strip sensitive headers specified in Retry.remove_headers_on_redirect when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by @christos-spearbit)

Deprecations and Removals
Bugfixes
View original

Upgraded? How did it go?

Discussion