Debian Package Tracker
Register | Log in
Subscribe

python-urllib3

HTTP library with thread-safe connection pooling for Python3

Choose email to subscribe with

general
  • source: python-urllib3 (main)
  • version: 1.26.16-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Daniele Tricoli [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.24.1-1
  • oldstable: 1.26.5-1~exp1
  • stable: 1.26.12-1
  • testing: 1.26.16-1
  • unstable: 1.26.16-1
versioned links
  • 1.24.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.5-1~exp1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.12-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.16-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-urllib3 (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 2.0.6 high
A new upstream version 2.0.6 is available, you should consider packaging it.
Created: 2022-11-18 Last update: 2023-10-08 02:41
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Created: 2023-10-05 Last update: 2023-10-07 18:08
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Created: 2023-10-05 Last update: 2023-10-07 18:08
4 security issues in buster high

There are 4 open security issues in buster.

1 important issue:
  • CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
3 issues postponed or untriaged:
  • CVE-2019-11236: (needs triaging) In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
  • CVE-2019-11324: (needs triaging) The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
  • CVE-2020-26137: (needs triaging) urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Created: 2023-10-05 Last update: 2023-10-07 18:08
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Created: 2023-10-05 Last update: 2023-10-07 18:08
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Created: 2023-10-05 Last update: 2023-10-07 18:08
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 1.26.16-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-06-30 12:27
news
[rss feed]
  • [2023-07-03] python-urllib3 1.26.16-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-29] Accepted python-urllib3 1.26.16-1 (source) into unstable (Daniele Tricoli)
  • [2022-09-25] python-urllib3 1.26.12-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-22] Accepted python-urllib3 1.26.12-1 (source) into unstable (Anthony Fok)
  • [2022-03-22] python-urllib3 1.26.9-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-19] Accepted python-urllib3 1.26.9-1 (source) into unstable (Daniele Tricoli)
  • [2022-03-16] python-urllib3 1.26.8-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-14] Accepted python-urllib3 1.26.8-1 (source) into unstable (Daniele Tricoli)
  • [2021-07-08] python-urllib3 1.26.5-1~exp1 MIGRATED to testing (Debian testing watch)
  • [2021-06-27] Accepted python-urllib3 1.26.5-1~exp1 (source) into unstable (Daniele Tricoli)
  • [2021-06-15] Accepted python-urllib3 1.19.1-1+deb9u1 (source all) into oldstable (Abhijith PA)
  • [2021-05-17] python-urllib3 1.26.4-1 MIGRATED to testing (Debian testing watch)
  • [2021-05-12] Accepted python-urllib3 1.26.4-1 (source) into unstable (Stefano Rivera)
  • [2021-01-06] python-urllib3 1.26.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-31] Accepted python-urllib3 1.26.2-1 (source) into unstable (Daniele Tricoli)
  • [2020-11-19] python-urllib3 1.25.11-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-14] Accepted python-urllib3 1.25.11-1 (source) into unstable (Dmitry Shachnev)
  • [2020-05-08] python-urllib3 1.25.9-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-02] Accepted python-urllib3 1.25.9-1 (source) into unstable (Scott Kitterman) (signed by: Donald Scott Kitterman)
  • [2020-04-08] python-urllib3 1.25.8-2 MIGRATED to testing (Debian testing watch)
  • [2020-04-01] Accepted python-urllib3 1.25.8-2 (source) into unstable (Sandro Tosi)
  • [2020-02-17] python-urllib3 1.25.8-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-11] Accepted python-urllib3 1.25.8-1 (source) into unstable (Håvard Flaget Aasen) (signed by: Utkarsh Gupta)
  • [2020-01-15] python-urllib3 1.25.6-5 MIGRATED to testing (Debian testing watch)
  • [2020-01-10] Accepted python-urllib3 1.25.6-5 (source) into unstable (Sandro Tosi)
  • [2019-12-10] python-urllib3 1.25.6-4 MIGRATED to testing (Debian testing watch)
  • [2019-12-05] Accepted python-urllib3 1.25.6-4 (source) into unstable (Daniele Tricoli)
  • [2019-12-02] Accepted python-urllib3 1.25.6-3 (source) into experimental (Daniele Tricoli)
  • [2019-10-27] Accepted python-urllib3 1.25.6-2 (source) into experimental (Daniele Tricoli)
  • [2019-10-12] Accepted python-urllib3 1.25.6-1 (source) into experimental (Drew Parsons)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.26.16-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing