Improper Certificate Validation in urllib3 - #VU150185
Published: September 16, 2026 / Updated: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and modify forwarded requests and responses.
The vulnerability exists due to improper certificate validation in the HTTPS proxy TLS configuration when handling TLS connections to HTTPS proxies. A remote attacker can impersonate an HTTPS proxy using a certificate accepted under the effective proxy TLS policy to disclose sensitive information and modify forwarded requests and responses.
Exploitation requires intercepting the connection to an HTTPS proxy.