-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 10 Jan 2026 18:20:00 +0100 Source: python-urllib3 Architecture: source Version: 2.5.0-2 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Santiago Vila <sanvila@debian.org> Closes: 1125062 Changes: python-urllib3 (2.5.0-2) unstable; urgency=medium . * Team upload. . [ Salvatore Bonaccorso ] * Fix security issue where decompression-bomb safeguards of the streaming API were bypassed when HTTP redirects were followed. (CVE-2026-21441) (Closes: #1125062) . [ Santiago Vila ] * Drop debian/.gitignore, dpkg-buildpackage dislikes it. * d/control: Drop "Rules-Requires-Root: no" (default). * d/control: Drop "Priority: optional" (default). * d/control: Update standards-version. Checksums-Sha1: 7cda2cc9918ab44b1a69124221ff48e7da1bb176 2404 python-urllib3_2.5.0-2.dsc c9e8f43d257af4c593dad8a3db7d7b26ca7ff457 39496 python-urllib3_2.5.0-2.debian.tar.xz 60d4e3c55a15ba18c514e050bc1acf01441cb0dc 5811 python-urllib3_2.5.0-2_source.buildinfo Checksums-Sha256: 3223b400eb98cdb08326114f179e4687ea4ac889aaf21090c5c5ff0dfa36c669 2404 python-urllib3_2.5.0-2.dsc eb395b6fb6b1bea9162fab2781607d4505802e2c41bc2dcb75b0bf42f8b63df9 39496 python-urllib3_2.5.0-2.debian.tar.xz deee2dd0010bdeedb2d8fb7302652663b4c52692c70ef768a854a708f2f9096b 5811 python-urllib3_2.5.0-2_source.buildinfo Files: 7531a860ede388eca756b72cd22ee7eb 2404 python optional python-urllib3_2.5.0-2.dsc 709e1e2490fb38cb5afce4c989bb71e9 39496 python optional python-urllib3_2.5.0-2.debian.tar.xz 7b9566355d2a151e9487200387a52993 5811 python optional python-urllib3_2.5.0-2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAmliitgACgkQQc5/C58b izLKDgf/e2wu7jHP2i2QeYPOSm4MKQXk9rCzc5nXwCGBhpMQjWhk/B7K+dFOfson LQ6CKCq+EJ6giCcBedZZ9fDQIv+vn/Ricuj8UQLM4th6dWe6995asaTJYL3U+PDQ Y9P5FgKxYeYH9xquGYkNboD/owp/sfKvuftzH26mK5ZK8J8o7RbjQCQ6RYz2Z8K8 WOnnsqOuV29AzffDd5Sq3aptfd4EpQDMOQ/HJdKlmHQOrwhYjw81PnkTY4YCiTSE 9jxw1lo0WN/FIewhJUMIRPaRN+v4pOtIHRaKumJ/rmWtliQIyjk8EB0KFz33hg+G CTGMTty0Y42qunWRnJge8gY2Vp8O8Q== =Eyzg -----END PGP SIGNATURE-----