Improper Certificate Validation in urllib3 - #VU150185

 

Improper Certificate Validation in urllib3 - #VU150185

Published: September 16, 2026 / Updated: September 18, 2026


Vulnerability identifier: #VU150185
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and modify forwarded requests and responses.

The vulnerability exists due to improper certificate validation in the HTTPS proxy TLS configuration when handling TLS connections to HTTPS proxies. A remote attacker can impersonate an HTTPS proxy using a certificate accepted under the effective proxy TLS policy to disclose sensitive information and modify forwarded requests and responses.

Exploitation requires intercepting the connection to an HTTPS proxy.


Affected software

urllib3

Remediation

Install security update from vendor's website.

urllib3 - update to 2.8.0

External References

Related Security Bulletins