NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1698 most downloaded on PyPI
An interactive, SSL/TLS-capable intercepting proxy for HTTP/1, HTTP/2, and WebSockets.
Last release 4 months ago
12 May 2026
Release timing varies
gaps range from 1 weeks to 5 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
88 releases · first in 2012
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
notBefore backdate remains below Chromium's 200-day limit.
(#8203, @emanuele-em)authority and subject key identifier mismatch errors when mitmproxy
is configured with a custom CA whose SubjectKeyIdentifier was not derived
as SHA-1 of the public key.
(#8214, @unique-jakub)IndexError in is_mostly_bin when exporting flows to HAR with payloads
that have a UTF-8 continuation byte at the 100-byte cutoff.
(#8196, @juliosuas)One column per quarter.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
CERT_EXPIRY to 199 days.
(#8142, @opstic)message.content.
(#8055, @Prinzhorn)--options output.
(#4423, @emanuele-em)view.settings.setval.toggle command to correctly use the provided key parameter instead of hardcoded "key" string.
(#8167, @nameearly)HTTP://).
(#8174, @emanuele-em)modify_body crash when replacement strings contain backslash sequences.
(#8046, @HueCodes)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
tcp_timeout option (default: 600 seconds).
Previously, the timeout was hardcoded to 10 minutes for all TCP connections.
(#7909, @keshavkrishnadav)bless from hex editors to avoid issues with macOS
(#7937, @caiquejjx)is_mostly_bin check to support chinese characters
(#7933, @caiquejjx, @mhils)@ts-expect-error directives.
(#7988, @DNEGEL3125)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
htpasswd file parser with a custom implementation to migrate off unmaintained
passlib dependency. The new parser only supports bcrypt and SHA-1 hashing.
Contributions for additional formats are welcome as long as they don't introduce new
dependencies.
(#7906, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
web_port option.
(#7827, @sujaldev)windows-2019 runner to windows-2025.
(#7801, @chedieck)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/ .
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
str with the prettified data.
Syntax highlighting is now signaled off-band (and based on tree-sitter).mitmproxy.dns.Message has been renamed to mitmproxy.dns.DNSMessage
(#7670, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/ .
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
web_password.
(#7554, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
web_password option replaces the randomly-generated token
authentication with a fixed secret that survives mitmproxy restarts.
(0bd573a, @mhils)xsrf_token cookie is now HttpOnly; SameSite=Strict.
(#7491, @mhils)ignore_hosts or allow_hosts.
(#7519, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
validate_inbound_headers is disabled.
(#7361, #7373, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
tun proxy mode that creates a virtual network device on Linux for transparent proxying.
(#7278, @mhils)browser.start command now supports Firefox.
(#7239, @sujaldev)modify_headers and stream_large_bodies options.
This may break users of modify_headers that rely on filters referencing the message body.
We expect this to be uncommon, but please make yourself heard if that's not the case.
(#7286, @lukant)protobuf library as it was no longer being used.
(#7327, @matthew16550)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
show_ignored_hosts option to display ignored flows in the UI.
This option is implemented as a temporary workaround and will be removed in the future.
(#6720, @NicolaiSoeborg)getaddrinfo-based fallback for DNS resolution if we are unable to
determine the operating system's name servers.
(#7122, @mhils)certs option without a matching private key.
(#7073, @mhils)STOP_SENDING QUIC frames.
(#7119, @mhils)Connection.tls_version now is QUICv1 instead of QUIC for QUIC.
(#7201, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
HttpConnectedHook and HttpConnectErrorHook.
(#6930, @errorxyz)allow_hosts.
(#7002, @JarLob, @mhils)typing.Sequence[str] to be an editable option.
(#7001, @errorxyz)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
v again.
(#6810, @mhils)-n is passed.
(#6819, @mhils)unbuffered (stdout/stderr) flag for the mitmdump PyInstaller build.
(#6821, @Prinzhorn)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
server_connect_error hook that is triggered when connection establishment fails.
(#6806, @haanhvu, @spacewasp, @mhils)client_connected handlers would crash mitmproxy.
(#6749, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
allow_hosts/ignore_hosts would break with IPv6 connections.
(#6614, @dqxpb)ca_file.
(#6666, @manselmi)content_view_lines_cutoff option to mitmdump
(#6692, @errorxyz)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
allow_hosts/ignore_hosts option now matches against the full host:port string.
(#6594, @LouisAsanaka)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
mitmproxy_rs.
This represents a major API change as UDP traffic is now exposed as streams
instead of a callback for each packet. (@mhils)ignore_hosts would terminate requests
instead of forwarding them.
(#6559, @mhils)ignore_hosts now waits for the entire HTTP headers if it suspects the connection to be HTTP.
(#6559, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
content-length headers
(#6548, @zanieb)allow_hosts/ignore_hosts options in WireGuard mode (#5930).
(#6513, @dsphper)ignore_hosts in WireGuard Mode.
(#6513, @dsphper)ignore_hosts now also takes HTTP/1 host headers into account.
(#6513, @dsphper)Key= instead of Key
(#5084, @Speedlulu)mitmweb splitter becoming drag and drop.
(#6492, @xBZZZZ)cryptography.x509.GeneralNames instead of list[str]
across the codebase. This fixes a regression introduced in mitmproxy 10.1.1 related to punycode domain encoding.
(#6537, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
replay-extra from CLI status bar.
(37d62ce, @mhils)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
server_replay_extra option to serverplayback to define behaviour
when replayable response is missing.
(#6465, @dkarandikar)You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Add support for reading HAR files using the existing flow loading APIs, e.g. mitmproxy -r example.har.
(#6335, @stanleygvi)
Add support for writing HAR files using the save.har command and the hardump option for mitmdump.
(#6368, @stanleygvi)
Packaging changes:
mitmproxy-rs does not depend on a protobuf compiler being available anymore,
we're now also providing a working source distribution for all platforms.mitmproxy-rs now depends on mitmproxy-macos. We only provide binary wheels for this package because
it contains a code-signed system extension. Building from source requires a valid Apple Developer Id, see CI for
details.mitmproxy-rs now depends on mitmproxy-windows. We only provide binary wheels for this package to
simplify our deployment process, see CI for how to build from source.(#6303, @mhils)
Increase maximum dump file size accepted by mitmweb (#6373, @t-wy)
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
replay.server.add command for adding flows to server replay buffer
(#5851, @italankin)Request.port now also updates the Host header if present.
This aligns with Request.host, which already does this.
(#5908, @sujaldev)esc key can now be used to exit the current view
(#6087, @sujaldev)server_replay_nopop option has been renamed to server_replay_reuse to avoid confusing double-negation.
(#6084, @prady0t, @Semnodime)ssl_insecure flag is set.
(#6281, @DurandA)onboarding_port option has been removed. The onboarding app now responds
to all requests for the hostname specified in onboarding_host.connection.Client and connection.Server now accept keyword arguments only.
This is a breaking change for custom addons that use these classes directly.You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
add_log event hook. Users should use the builtin logging module instead.
See the docs for details and upgrade instructions.
(#5590, @mhils)mitmproxy.ctx.log in favor of Python's builtin logging module.
See the docs for details and upgrade instructions.
(#5590, @mhils)mode option is now a list of server specs instead of a single spec.
The CLI interface is unaffected, but users may need to update their config.yaml.
(#5393, @mhils)connection_strategy to lazy now also disables early
upstream connections to fetch TLS certificate details.
(#5487, @mhils)tls_version_server_min and tls_version_server_max options.
(#5546, @mhils)content_view_lines_cutoff.
(#5548, @sanlengjingvv)Changes: See CHANGELOG.md. You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md. You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md. You can find the latest release packages at https://mitmproxy.org/downloads/.
Changes: See CHANGELOG.md. You can find the latest release packages at https://mitmproxy.org/downloads/.
mailcap module.
(#5297, @KORraNpl)Check out our release announcement blog post! 🎉
Check out our release announcement blog post! 🎉
You can find the latest release packages at https://mitmproxy.org/downloads/.
tls_{established,failed}_{client,server} event hooks
to record negotiation success/failure (@mhils, #4790)client_replay_concurrency option, which allows more than one client replay request to be in-flight at a time. (@rbdixon)view.flows.resolve (#4916, @rbdixon)running() is invoked twice on startup (#3584, @mhils)n new flow keybind to mitmweb (#5061, @ianklatzco)WebSocketMessage.injected flag (@Prinzhorn)Flow.live, which signals if a flow belongs to a currently active connection. (#4207, @mhils)--set options (#5067, @marwinxxii)Do not add a Content-Length header for chunked HTTP/1 messages (@matthewhughes934)
You can find the latest release packages at https://mitmproxy.org/downloads/.
CVE-2021-39214: Fix request smuggling vulnerabilities reported by @chinchila
You can find the latest release packages at https://mitmproxy.org/downloads/.
Fix a WebSocket crash introduced in 7.0.1 (@mhils)
You can find the latest release packages at https://mitmproxy.org/downloads/.
Performance: Re-use OpenSSL contexts to enable TLS session resumption (@mhils)
Server.address (@SaladDais)You can find the latest release packages at https://mitmproxy.org/downloads/.
Check out our release announcement blog post! 🎉
Check out our release announcement blog post! 🎉
You can find the latest release packages at https://mitmproxy.org/downloads/.
This release fixes another bug in mitmweb's serialization process. All other tools are unaffected.
This release fixes another bug in mitmweb's serialization process. All other tools are unaffected.
You can find the latest release packages at https://mitmproxy.org/downloads/.
This release fixes a bug in mitmweb's serialization process. All other tools are unaffected.
This release fixes a bug in mitmweb's serialization process. All other tools are unaffected.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Check out our release announcement blog post! 🎉 🔗
Check out our release announcement blog post! 🎉 🔗
You can find the latest release packages at https://mitmproxy.org/downloads/.
Check out our release announcement blog post! 🎉 🔗
Check out our release announcement blog post! 🎉 🔗
@charset to decode CSS files if available (@prinzhorn)console_strip_trailing_newlines, and no longer strip trailing newlines by default (@capt8bit)deflateRaw for Content-Encoding's (@kjoconnor)You can find the latest release packages at https://mitmproxy.org/downloads/.
Check out our release announcement blog post! 🎉 🔗
Check out our release announcement blog post! 🎉 🔗
You can find the latest release packages at https://mitmproxy.org/downloads/.
Fixed Docker images not starting due to missing shell
Reduce leaf certificate validity to one year due to upcoming browser changes (@mhils)
Major Changes
Full Changelog
You can find the latest release packages at https://mitmproxy.org/downloads/.
Fixed precompiled Linux binaries to not crash in table mode.
You can find the latest release packages on https://mitmproxy.org/downloads/.
Security: Fixed command injection vulnerabilities when exporting flows as curl/httpie commands (@cript0nauta)
You can find the latest release packages on https://mitmproxy.org/downloads/.
Security: Protect mitmweb against DNS rebinding. (CVE-2018-14505, @atx)
You can find the latest release packages on https://mitmproxy.org/downloads/.
Add support for IPv6 transparent mode on Windows
You can find the latest release packages on our snapshot server.
The previous release had a packaging issue, so we bumped it to v4.0.1 and re-released it. This contains no actual bugfixes or new features.
The previous release had a packaging issue, so we bumped it to v4.0.1 and re-released it. This contains no actual bugfixes or new features.
Please see the v4.0.0 release notes!
mitmproxy now requires Python 3.6!
SO_KEEPALIVE (#3076)config.yaml under the configuration directory).allow_remote got replaced by block_global and block_private (#3100)cadir option has been renamed to confdirctx.log.info explicitly.~ in paths during the cut command (#3078)Fix an issue that caused mitmproxy to not retry HTTP requests on timeout.
A minor release that actually includes the fix meant for 3.0.2.
A minor release that actually includes the fix meant for 3.0.2.
Fix an issue that caused mitmproxy to lose keyboard control after spawning an external editor.
Fix an issue that caused mitmproxy to lose keyboard control after spawning an external editor.
A quick point release to fix a bug that broke quoted arguments in the console command editor.
A quick point release to fix a bug that broke quoted arguments in the console command editor.
Mitmproxy doesn’t have telemetry and collects as little data as possible on its users. We rely on your manual feedback to let us know what to build. Please take a moment to fill in the 2018 mitmproxy user survey - this feeds directly into our dev priorities for the next year.
Your coding agent can read these notes before it upgrades. Set up the MCP server →