-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jun 2026 07:05:34 +0200 Source: python-urllib3 Architecture: source Version: 1.26.5-1~exp1+deb11u4 Distribution: bullseye-security Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1136653 Changes: python-urllib3 (1.26.5-1~exp1+deb11u4) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Team. * Fix CVE-2026-44431: Sensitive headers forwarded across origins in proxied low-level redirects. (Closes: #1136653) Checksums-Sha1: e60ef4634af1b3c7e45d2621835c9cf7359fcf8b 2250 python-urllib3_1.26.5-1~exp1+deb11u4.dsc 31d7e239a9dbaf0a9602d3f272d911d05f98d8a0 292865 python-urllib3_1.26.5.orig.tar.gz 9cdd91fd802341bec6f79d7009d12f31d1900b2d 20548 python-urllib3_1.26.5-1~exp1+deb11u4.debian.tar.xz fdfecafbe0e219c99bcd40a9ee748ead942e6b20 7121 python-urllib3_1.26.5-1~exp1+deb11u4_source.buildinfo Checksums-Sha256: 7c15ee614e179d9f1b61781e84ed3aee1a0b21495ff7c6e8c3b49c76321b70f0 2250 python-urllib3_1.26.5-1~exp1+deb11u4.dsc a7acd0977125325f516bda9735fa7142b909a8d01e8b2e4c8108d0984e6e0098 292865 python-urllib3_1.26.5.orig.tar.gz c8140111547678fdf872faadfc749850a3996effddb1cf0f2f5f23b66c7e9783 20548 python-urllib3_1.26.5-1~exp1+deb11u4.debian.tar.xz 1ed767ab4f0ec4569438683ab5a1cddd749ed2610a7d21020144cd8b05f9f0da 7121 python-urllib3_1.26.5-1~exp1+deb11u4_source.buildinfo Files: e3d0d07d48c9f3d76b5a5612c4975829 2250 python optional python-urllib3_1.26.5-1~exp1+deb11u4.dsc 33b8670413e684188b1340204bc8ad75 292865 python optional python-urllib3_1.26.5.orig.tar.gz 90ec581e0294727bbd361fb9b2d318bd 20548 python optional python-urllib3_1.26.5-1~exp1+deb11u4.debian.tar.xz 1840b444538fa793ac406050af4a3c6c 7121 python optional python-urllib3_1.26.5-1~exp1+deb11u4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmo+Ms8ACgkQ05pJnDwh pVLTchAAx0FqcZMQlgzDTRM7YLh2eXoBEzQNvUZBKvK7Bk7REDfsoNKpfWEUPGGX WTzFcNEkfsQqfvXJeknEnFyhFqxgHL7SBgOncf+MMh7QHpso6aVVzUtwpRzAr5HT XQKsR7u1DHfpU+oE3C/gmgsQYvIfU1VUCw2Eyx626UQpmfnRIL3oAiVXy97dlW8U AxAoivOayf24Nln9BvHrNgQgLNU1YTvkzLaBp5ltVuAG6GUHU2B/WIh+yjp4ETpZ ury8M/Tykb/uFZJ2hsDpmKEcvfocHvggDUtN6dvf4fvl1rt1U3Fyytr7s2Q9yZzK 872osAz+pX7BJ4TNz3vjEpmlXIOblFG8Izd2OkrQ+ZSnel2mcEEu5k3TiwlnyvnY xQOVkoJFkesaWcX6OXxl82Sv8wkPbgVDB6T78xXeyGOj+qFDBhVsWXQ5smM8P3vM 1YjFQjo7wEN13Nwj4W8SgxcUrCE6/kdy1MPpGoEtSSzUkOPUHYpFhB5GtBoZB3qK 4UT38Nfs0jKvLsj0djYDwZrMnUzqpbShAN1Qvk6px4JPeMCYKM2WVxLX+6cCy054 yMK1kJVBAwhPwAm/npRShm+0d9ehnbpwT2iGBGrtT3nT7ZqH6NuUq86yFA7EueXG UDGxY9YtQwYfhYjWgahdrK1SvbtJxQDig0yIRagUfv5ixsk83+A= =6IyG -----END PGP SIGNATURE-----