| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| urllib3-2.7.0-py3-none-any.whl | 2026-05-07 | 131.1 kB | |
| urllib3-2.7.0.tar.gz | 2026-05-07 | 433.6 kB | |
| 2.7.0 source code.tar.gz | 2026-05-07 | 454.0 kB | |
| 2.7.0 source code.zip | 2026-05-07 | 515.0 kB | |
| README.md | 2026-05-07 | 3.2 kB | |
| Totals: 5 Items | 1.5 MB | 3 | |
🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Security
Addressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.
-
Decompression-bomb safeguards of the streaming API were bypassed:
-
When
HTTPResponse.drain_conn()was called after the response had been read and decompressed partially. (Reported by @Cycloctane) - During the second
HTTPResponse.read(amt=N)orHTTPResponse.stream(amt=N)call when the response was decompressed using the official Brotli library. (Reported by @kimkou2024)
See GHSA-mf9v-mfxr-j63j for details.
- HTTP pools created using
ProxyManager.connection_from_urldid not strip sensitive headers specified inRetry.remove_headers_on_redirectwhen redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by @christos-spearbit)
Deprecations and Removals
- Used
FutureWarninginstead ofDeprecationWarningfor better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (https://github.com/urllib3/urllib3/issues/3764) - Removed support for end-of-life Python 3.9. (https://github.com/urllib3/urllib3/issues/3720)
- Removed support for end-of-life PyPy3.10. (https://github.com/urllib3/urllib3/issues/4979)
- Bumped the minimum supported pyOpenSSL version to 19.0.0. (https://github.com/urllib3/urllib3/issues/3777)
Bugfixes
- Fixed a bug where
HTTPResponse.read(amt=None)was ignoring decompressed data buffered from previous partial reads. (https://github.com/urllib3/urllib3/issues/3636) - Fixed a bug where
HTTPResponse.read()could cache only part of the response after a partial read whencache_content=True. (https://github.com/urllib3/urllib3/issues/4967) - Fixed
HTTPResponse.stream()andHTTPResponse.read_chunked()to handleamt=0. (https://github.com/urllib3/urllib3/issues/3793) - Updated
_TYPE_BODYtype alias to include missingIterable[str], matching the documented and runtime behavior of chunked request bodies. (https://github.com/urllib3/urllib3/issues/3798) - Fixed
LocationParseErrorwhen paths resembling schemeless URIs were passed toHTTPConnectionPool.urlopen(). (https://github.com/urllib3/urllib3/issues/3352) - Fixed
BaseHTTPResponse.readinto()type annotation to acceptmemoryviewin addition tobytearray, matching theio.RawIOBase.readintocontract and enabling use withio.BufferedReaderwithout type errors. (https://github.com/urllib3/urllib3/issues/3764)