NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #5 most downloaded on PyPI
HTTP library with thread-safe connection pooling, file post, and more.
Last release 19 days ago
15 Sep 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
17 years old
109 releases · first in 2009
…upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Fixed the following security issues:
HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)Important
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.
Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.
Note
CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.
Retry option allowed_methods to retry any verb. (#5044)Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)
Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)
Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)
Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)
Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)
Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)
Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)
Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)
Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)
Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)
Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)
Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)
Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.
HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)
Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)
Fixed an AttributeError on Python built with OpenSSL 4+, where ssl.PROTOCOL_TLSv1 no longer exists. (#5097)
Fixed urllib3.contrib.pyopenssl to use cryptography APIs when reading a certificate subject and loading encrypted private keys, avoiding DeprecationWarning raised by pyOpenSSL 26.3.0+. (#5103)
Fixed handling of HTTP 303 redirects for requests with chunked or file-like bodies. (#5161)
Fixed assert_fingerprint() to raise SSLError instead of binascii.Error when a fingerprint has a supported length but contains non-hexadecimal characters. (#5211)
test dependency group containing the minimum dependencies needed to run the test suite, intended for downstream packagers. The dev-base and mypy groups now include this new group via include-group, removing duplication. (#3594)One column per quarter.
Used FutureWarning instead of DeprecationWarning for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features…
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Addressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.
Decompression-bomb safeguards of the streaming API were bypassed:
HTTPResponse.drain_conn() was called after the response had been read and decompressed partially. (Reported by @Cycloctane)HTTPResponse.read(amt=N) or HTTPResponse.stream(amt=N) call when the response was decompressed using the official Brotli library. (Reported by @kimkou2024)See GHSA-mf9v-mfxr-j63j for details.
HTTP pools created using ProxyManager.connection_from_url did not strip sensitive headers specified in Retry.remove_headers_on_redirect when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by @christos-spearbit)
FutureWarning instead of DeprecationWarning for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (#3763)HTTPResponse.read(amt=None) was ignoring decompressed data buffered from previous partial reads. (#3636)HTTPResponse.read() could cache only part of the response after a partial read when cache_content=True. (#4967)HTTPResponse.stream() and HTTPResponse.read_chunked() to handle amt=0. (#3793)_TYPE_BODY type alias to include missing Iterable[str], matching the documented and runtime behavior of chunked request bodies. (#3798)LocationParseError when paths resembling schemeless URIs were passed to HTTPConnectionPool.urlopen(). (#3352)BaseHTTPResponse.readinto() type annotation to accept memoryview in addition to bytearray, matching the io.RawIOBase.readinto contract and enabling use with io.BufferedReader without type errors. (#3764)…bypassed when HTTP redirects were followed. ( CVE-2026-21441 reported by @D47A , 8.9 High, GHSA-38jv-5279-wg99 )
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Retry-After times greater than 6 hours as 6 hours by default. (#3743)urllib3.connection.VerifiedHTTPSConnection on Emscripten. (#3752)Fixed a high-severity security issue where decompression-bomb safeguards of the streaming API were bypassed when HTTP redirects were followed. (GHSA-38jv-5279-wg99)
Started treating Retry-After times greater than 6 hours as 6 hours by default. (#3743)
Fixed urllib3.connection.VerifiedHTTPSConnection on Emscripten. (#3752)
🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
HTTPResponse.read_chunked() to properly handle leftover data in the decoder's buffer when reading compressed chunked responses. (#3734)🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
HTTPResponse.getheaders() and HTTPResponse.getheader() methods. (#3731)Reading small chunks of compressed data is safer and much more efficient now. ( CVE-2025-66471 reported by @Cycloctane , 8.9 High, GHSA-2xpw-w6gg-jr37…
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Content-Encoding header, potentially leading to a denial of service (DoS) attack by exhausting system resources during decoding. The number of allowed chained encodings is now limited to 5. (CVE-2025-66418 reported by @illia-v, 8.9 High, GHSA-gm62-xv2j-4w53)Important
urllib3[brotli] extra, but your environment contains a Brotli/brotlicffi/brotlipy package anyway, make sure to upgrade it to at least Brotli 1.2.0 or brotlicffi 1.2.0.0 to benefit from the security fixes and avoid warnings. Prefer using urllib3[brotli] to install a compatible Brotli package automatically.urllib3.response.ContentDecoder.HTTPHeaderDict using bytes keys. (#3653)HTTPConnection. (#3666)HTTPResponse.getheaders() method in favor of HTTPResponse.headers. Removed the HTTPResponse.getheader(name, default) method in favor of HTTPResponse.headers.get(name, default). (#3622)urllib3.PoolManager when an integer is passed for the retries parameter. (#3649)HTTPConnectionPool when used in Emscripten with no explicit port. (#3664)SSLKEYLOGFILE with expandable variables. (#3700)zstd extra to install backports.zstd instead of zstandard on Python 3.13 and before. (#3693)BytesQueueBuffer class. (#3710)Pool managers now properly control redirects when retries is passed — CVE-2025-50181 reported by @sandumjacob (5.3 Medium, GHSA-pq67-6m6q-mj2v )
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
urllib3 2.5.0 fixes two moderate security issues:
retries is passed — CVE-2025-50181 reported by @sandumjacob (5.3 Medium, GHSA-pq67-6m6q-mj2v)compression.zstd module that is new in Python 3.14. See PEP 784 for more information. (#3610)hatch-vcs (#3612)Added support for the compression.zstd module that is new in Python 3.14. See PEP 784 for more information. (#3610)
Added support for version 0.5 of hatch-vcs (#3612)
Fixed a security issue where restricting the maximum number of followed redirects at the urllib3.PoolManager level via the retries parameter did not work.
Made the Node.js runtime respect redirect parameters such as retries and redirects.
Raised exception for HTTPResponse.shutdown on a connection already released to the pool. (#3581)
Fixed incorrect CONNECT statement when using an IPv6 proxy with connection_from_host. Previously would not be wrapped in []. (#3615)
🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
verify_flags option to create_urllib3_context with a default of VERIFY_X509_PARTIAL_CHAIN and VERIFY_X509_STRICT for Python 3.13+. (#3571)🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
HTTPResponse.shutdown() to stop any ongoing or future reads for a specific response. It calls shutdown(SHUT_RD) on the underlying socket. This feature was sponsored by LaunchDarkly. (#2868)--experimental-wasm-stack-switching. (#3400)proxy_is_tunneling property to HTTPConnection and HTTPSConnection. (#3285)NewConnectionError and NameResolutionError. (#3480)Full Changelog: 2.2.3...2.3.0
🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
HTTPConnection.default_socket_options. (#3448)HTTP/2 support is still in early development.
h2 (https://pypi.org/project/h2/) usage. Now only accepting supported h2 major version 4.x.x. (#3290)Full Changelog: 2.2.2...2.2.3
Added support for Python 3.13. (#3473)
Fixed the default encoding of chunked request bodies to be UTF-8 instead of ISO-8859-1. All other methods of supplying a request body already use UTF-8 starting in urllib3 v2.0. (#3053)
Fixed ResourceWarning on CONNECT with Python < 3.11.4 by backporting https://github.com/python/cpython/issues/103472. (#3252)
Adjust tolerance for floating-point comparison on Windows to avoid flakiness in CI (#3413)
Fixed a crash where certain standard library hash functions were absent in restricted environments. (#3432)
Fixed mypy error when adding to HTTPConnection.default_socket_options. (#3448)
HTTP/2 support is still in early development.
Excluded Transfer-Encoding: chunked from HTTP/2 request body (#3425)
Added version checking for h2 (https://pypi.org/project/h2/) usage.
Now only accepting supported h2 major version 4.x.x. (#3290)
Added a probing mechanism for determining whether a given target origin supports HTTP/2 via ALPN. (#3301)
Add support for sending a request body with HTTP/2 (#3302)
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financi
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Proxy-Authorization header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_on_redirect.amt to read methods of http.client.HTTPResponse as an alternative to None. (#3122)typing.Self. (#3363)Full Changelog: https://github.com/urllib3/urllib3/compare/2.2.1...2.2.2
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financi
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
InsecureRequestWarning was emitted for HTTPS connections when using Emscripten. (#3331)HTTPConnectionPool.urlopen to stop automatically casting non-proxy headers to HTTPHeaderDict. This change was premature as it did not apply to proxy headers and HTTPHeaderDict does not handle byte header values correctly yet. (#3343)ProtocolError to InvalidChunkLength when response terminates before the chunk length is sent. (#2860)ProtocolError to be more verbose on incomplete reads with excess content. (#3261):tada: This release adds experimental support for [using urllib3 in the browser with Pyodide](https://urllib3.readthedocs.io/en/stable/reference/contr
:tada: This release adds experimental support for using urllib3 in the browser with Pyodide! :tada:
Thanks to Joe Marshall (@joemarshall) for contributing this feature. This change was possible thanks to work done in urllib3 v2.0 to detach our API from http.client. Please report all bugs to the urllib3 issue tracker.
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
HTTPResponse.read1() method. (#3186)HTTPConnection.proxy_is_verified and HTTPSConnection.proxy_is_verified to be always set to a boolean after connecting to a proxy. It could be None in some cases previously. (#3130)headers passed in a request with json= would be mutated (#3203)HTTPSConnection.is_verified to be set to False when connecting from a HTTPS proxy to an HTTP target. It was set to True previously. (#3267)Note for downstream distributors: To run integration tests, you now need to run the tests a second time with the --integration pytest flag. (#3181)
Removed support for the deprecated urllib3[secure] extra.
Read the v2 migration guide for help upgrading to the latest version of urllib3.
Made body stripped from HTTP requests changing the request method to GET after HTTP 303 "See Other" redirect responses. (GHSA-g4mx-q9vg-27p4)
Added the Cookie header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set vi
Cookie header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_on_redirect. (GHSA-v845-jxx5-vc9f)Allowed pyOpenSSL third-party module without any deprecation warning. #3126
Added support for union operators to HTTPHeaderDict
HTTPHeaderDict (#2254)BaseHTTPResponse to urllib3.__all__ (#3078)urllib3.connection.HTTPConnection to raise the http.client.connect audit event to have the same behavior as the standard library HTTP client (#2757)Deprecated URLs which don't have an explicit scheme #2950
assert_hostname=False to correctly skip hostname check. #3051Fixed HTTPResponse.stream() to continue yielding bytes if buffered decompressed data was still available to be read even if the underlying socket is c
HTTPResponse.stream() to continue yielding bytes if buffered decompressed data was still available to be read even if the underlying socket is closed. This prevents a compressed response from being truncated. (https://github.com/urllib3/urllib3/issues/3009)Fixed a socket leak when fingerprint or hostname verifications fail.
HTTPResponse.read(0) was the first read call or when the internal response body buffer was otherwise empty. (#2998)Removed fallback on certificate commonName in match_hostname() function. This behavior was deprecated in May 2000 in RFC 2818. Instead only subjectAlt…
Read the v2.0 migration guide for help upgrading to the latest version of urllib3.
commonName in match_hostname() function. This behavior was deprecated in May 2000 in RFC 2818. Instead only subjectAltName is used to verify the hostname by default. To enable verifying the hostname against commonName use SSLContext.hostname_checks_common_name = True (#2113).ssl module compiled with LibreSSL, CiscoSSL, wolfSSL, and all other OpenSSL alternatives. Python is moving to require OpenSSL with PEP 644 (#2168).ImportError is raised (#2168).urllib3.contrib.appengine.AppEngineManager and support for Google App Engine Standard Environment (#2044).Retry options method_whitelist, DEFAULT_REDIRECT_HEADERS_BLACKLIST (#2086).urllib3.HTTPResponse.from_httplib (#2648).None for the request_context parameter of urllib3.PoolManager.connection_from_pool_key. This change should have no effect on users as the default value of None was an invalid option and was never used (#1897).urllib3.request module. urllib3.request.RequestMethods has been made a private API. This change was made to ensure that from urllib3 import request imported the top-level request() function instead of the urllib3.request module (#2269).urllib3.contrib.pyopenssl even when support is available from the compiled OpenSSL library (#2233).urllib3.contrib.ntlmpool module (#2339).DEFAULT_CIPHERS, HAS_SNI, USE_DEFAULT_SSLCONTEXT_CIPHERS, from the private module urllib3.util.ssl_ (#2168).urllib3.exceptions.SNIMissingWarning (#2168)._prepare_conn method from HTTPConnectionPool. Previously this was only used to call HTTPSConnection.set_cert() by HTTPSConnectionPool (#1985).tls_in_tls_required property from HTTPSConnection. This is now determined from the scheme parameter in HTTPConnection.set_tunnel() (#1985).HTTPResponse.getheaders() and HTTPResponse.getheader() which will be removed in urllib3 v2.1.0. Instead use HTTPResponse.headers and HTTPResponse.headers.get(name, default). (#1543, #2814).urllib3.contrib.pyopenssl module which will be removed in urllib3 v2.1.0 (#2691).urllib3.contrib.securetransport module which will be removed in urllib3 v2.1.0 (#2692).ssl_version option in favor of ssl_minimum_version. ssl_version will be removed in urllib3 v2.1.0 (#2110).strict parameter as it's not longer needed in Python 3.x. It will be removed in urllib3 v2.1.0 (#2267)NewConnectionError.pool attribute which will be removed in urllib3 v2.1.0 (#2271).format_header_param_html5 and format_header_param in favor of format_multipart_header_param (#2257).RequestField.header_formatter parameter which will be removed in urllib3 v2.1.0 (#2257).HTTPSConnection.set_cert() method. Instead pass parameters to the HTTPSConnection constructor (#1985).HTTPConnection.request_chunked() method which will be removed in urllib3 v2.1.0. Instead pass chunked=True to HTTPConnection.request() (#1985).urllib3.request function which uses a preconfigured module-global PoolManager instance (#2150).json parameter to urllib3.request(), PoolManager.request(), and ConnectionPool.request() methods to send JSON bodies in requests. Using this parameter will set the header Content-Type: application/json if Content-Type isn't already defined. Added support for parsing JSON response bodies with HTTPResponse.json() method (#2243).urllib3 module (#1897).ssl_minimum_version and ssl_maximum_version options which set SSLContext.minimum_version and SSLContext.maximum_version (#2110).zstandard 1.18.0 or later is installed. Added the zstd extra which installs the zstandard package (#1992).urllib3.response.BaseHTTPResponse class. All future response classes will be subclasses of BaseHTTPResponse (#2083).FullPoolError which is raised when PoolManager(block=True) and a connection is returned to a full pool (#2197).HTTPHeaderDict to the top-level urllib3 namespace (#2216).HTTPHeaderDict to provide headers for a request, by default duplicate header values will be repeated. But if combine=True is passed into a call to HTTPHeaderDict.add, then the added header value will be merged in with an existing value into a comma-separated list (X-My-Header: foo, bar) (#2242).NameResolutionError exception when a DNS error occurs (#2305).proxy_assert_hostname and proxy_assert_fingerprint kwargs to ProxyManager (#2409).backoff_max parameter to the Retry class. If a custom backoff_max is provided to the Retry class, it will replace the Retry.DEFAULT_BACKOFF_MAX (#2494).authority property to the Url class as per RFC 3986 3.2. This property should be used in place of netloc for users who want to include the userinfo (auth) component of the URI (#2520).scheme parameter to HTTPConnection.set_tunnel to configure the scheme of the origin being tunnelled to (#1985).is_closed, is_connected and has_connected_to_proxy properties to HTTPConnection (#1985).backoff_jitter parameter to Retry. (#2952)urllib3.response.HTTPResponse.read to respect the semantics of io.BufferedIOBase regardless of compression. Specifically, this method:
urllib3.response.HTTPResponse.read call to issue a single system call, you need to disable decompression by setting decode_content=False (#2128).urllib3.HTTPConnection.getresponse to return an instance of urllib3.HTTPResponse instead of http.client.HTTPResponse (#2648).ssl_version to instead set the corresponding SSLContext.minimum_version and SSLContext.maximum_version values. Regardless of ssl_version passed SSLContext objects are now constructed using ssl.PROTOCOL_TLS_CLIENT (#2110).SSLContext.minimum_version to be TLSVersion.TLSv1_2 in line with Python 3.10 (#2373).ProxyError to wrap any connection error (timeout, TLS, DNS) that occurs when connecting to the proxy (#2482).urllib3.util.create_urllib3_context to not override the system cipher suites with a default value. The new default will be cipher suites configured by the operating system (#2168).multipart/form-data header parameter formatting matches the WHATWG HTML Standard as of 2021-06-10. Control characters in filenames are no longer percent encoded (#2257).ssl module isn't available from SSLError to ImportError (#2589).HTTPConnection.request() to always use lowercase chunk boundaries when sending requests with Transfer-Encoding: chunked (#2515).enforce_content_length default to True, preventing silent data loss when reading streamed responses (#2514).HTTPHeaderDict to use dict instead of collections.OrderedDict for better performance (#2080).urllib3.contrib.pyopenssl module to wrap OpenSSL.SSL.Error with ssl.SSLError in PyOpenSSLContext.load_cert_chain (#2628).socket.error to OSError (#2120).HTTPConnection and HTTPSConnection constructors to be keyword-only except host and port (#1985).HTTPConnection.getresponse() to set the socket timeout from HTTPConnection.timeout value before reading data from the socket. This previously was done manually by the HTTPConnectionPool calling HTTPConnection.sock.settimeout(...) (#1985)._proxy_host property to _tunnel_host in HTTPConnectionPool to more closely match how the property is used (value in HTTPConnection.set_tunnel()) (#1985).Retry.BACK0FF_MAX to be Retry.DEFAULT_BACKOFF_MAX.SSLContext.check_hostname when possible (#2452).server_hostname to behave like other parameters only used by HTTPSConnectionPool (#2537).blocksize to 16KB to match OpenSSL's default read amounts (#2348).HTTPResponse.read() to raise an error when calling with decode_content=False after using decode_content=True to prevent data loss (#2800).PoolManager with many distinct origins would cause connection pools to be closed while requests are in progress (#1252).HTTPConnection instance would erroneously reuse the socket read timeout value from reading the previous response instead of a newly configured connect timeout. Instead now if HTTPConnection.timeout is updated before sending the next request the new timeout value will be used (#2645).socket.error.errno when raised from pyOpenSSL's OpenSSL.SSL.SysCallError (#2118).HTTPSConnection.socket_options to match HTTPConnection (#2213).headers would be modified by the remove_headers_on_redirect feature (#2272).urllib3.util.connection.create_connection() (#2277).HTTPConnection.connect() fails (#2571).urllib3.contrib.pyopenssl.WrappedSocket and urllib3.contrib.securetransport.WrappedSocket close methods (#2970)Removed the setup.py shim, python setup.py install will print [Errno 2] No such file or directory instead of a warning to use pip
setup.py shim, python setup.py install will print [Errno 2] No such file or directory instead of a warning to use pip (#2975)backoff_jitter parameter to Retry (#2952)urllib3.contrib.pyopenssl.WrappedSocket and urllib3.contrib.securetransport.WrappedSocket close methods (#2970)Read the [v2.0 migration guide](https://urllib3.readthedocs.io/en/latest/v2-migration-guide.html) for help upgrading to the latest version of urllib3.
Read the v2.0 migration guide for help upgrading to the latest version of urllib3.
add_stderr_logger (#2839)PoolKey.key_retries by adding bool to the union (#2865)Changed HTTPResponse.getheaders() and .getheader() to previous behavior in 1.26.x. Instead we are deprecating these methods in favor of HTTPResponse.h…
Read the v2.0 migration guide for help upgrading to the latest version of urllib3.
HTTPResponse.read() to raise an error when calling with decode_content=False after using decode_content=True to prevent data loss (https://github.com/urllib3/urllib3/issues/2800).HTTPResponse.getheaders() and .getheader() to previous behavior in 1.26.x. Instead we are deprecating these methods in favor of HTTPResponse.headers.items() and HTTPResponse.headers.get(). Both deprecated methods will be removed in v2.1.0 (https://github.com/urllib3/urllib3/issues/2814)Removed fallback on certificate commonName in match_hostname() function. This behavior was deprecated in May 2000 in RFC 2818. Instead only subjectAlt…
Read the v2.0 migration guide for help upgrading to the latest version of urllib3!
urllib3 module (#1897).ssl_minimum_version and ssl_maximum_version options which set
SSLContext.minimum_version and SSLContext.maximum_version (#2110).zstandard 1.18.0 or later is installed.
Added the zstd extra which installs the zstandard package (#1992).urllib3.response.BaseHTTPResponse class. All future response classes will be subclasses of BaseHTTPResponse (#2083).urllib3.request function which uses a preconfigured module-global PoolManager instance (#2150).FullPoolError which is raised when PoolManager(block=True) and a connection is returned to a full pool (#2197).HTTPHeaderDict to the top-level urllib3 namespace (#2216).json parameter to urllib3.request(), PoolManager.request(), and ConnectionPool.request() methods to send JSON bodies in requests. Using this parameter will set the header Content-Type: application/json if Content-Type isn't already defined.
Added support for parsing JSON response bodies with HTTPResponse.json() method (#2243).HTTPHeaderDict to provide headers for a request, by default duplicate
header values will be repeated. But if combine=True is passed into a call to
HTTPHeaderDict.add, then the added header value will be merged in with an existing
value into a comma-separated list (X-My-Header: foo, bar) (#2242).NameResolutionError exception when a DNS error occurs (#2305).proxy_assert_hostname and proxy_assert_fingerprint kwargs to ProxyManager (#2409).backoff_max parameter to the Retry class.
If a custom backoff_max is provided to the Retry class, it
will replace the Retry.DEFAULT_BACKOFF_MAX (#2494).authority property to the Url class as per RFC 3986 3.2. This property should be used in place of netloc for users who want to include the userinfo (auth) component of the URI (#2520).scheme parameter to HTTPConnection.set_tunnel to configure the scheme of the origin being tunnelled to (#1985).is_closed, is_connected and has_connected_to_proxy properties to HTTPConnection (#1985).commonName in match_hostname() function.
This behavior was deprecated in May 2000 in RFC 2818. Instead only subjectAltName
is used to verify the hostname by default. To enable verifying the hostname against
commonName use SSLContext.hostname_checks_common_name = True (#2113).ssl module compiled with LibreSSL, CiscoSSL,
wolfSSL, and all other OpenSSL alternatives. Python is moving to require OpenSSL with PEP 644 (#2168).ImportError is raised (#2168).urllib3.contrib.appengine.AppEngineManager and support for Google App Engine Standard Environment (#2044).Retry options method_whitelist, DEFAULT_REDIRECT_HEADERS_BLACKLIST (#2086).urllib3.HTTPResponse.from_httplib (#2648).None for the request_context parameter of urllib3.PoolManager.connection_from_pool_key. This change should have no effect on users as the default value of None was an invalid option and was never used (#1897).urllib3.request module. urllib3.request.RequestMethods has been made a private API.
This change was made to ensure that from urllib3 import request imported the top-level request()
function instead of the urllib3.request module (#2269).urllib3.contrib.pyopenssl even when support is available from the compiled OpenSSL library (#2233).urllib3.contrib.ntlmpool module (#2339).DEFAULT_CIPHERS, HAS_SNI, USE_DEFAULT_SSLCONTEXT_CIPHERS, from the private module urllib3.util.ssl_ (#2168).urllib3.exceptions.SNIMissingWarning (#2168)._prepare_conn method from HTTPConnectionPool. Previously this was only used to call HTTPSConnection.set_cert() by HTTPSConnectionPool (#1985).tls_in_tls_required property from HTTPSConnection. This is now determined from the scheme parameter in HTTPConnection.set_tunnel() (#1985).urllib3.response.HTTPResponse.read to respect the semantics of io.BufferedIOBase regardless of compression. Specifically, this method:
urllib3.response.HTTPResponse.read call to issue a single system call, you need to disable decompression by setting decode_content=False (#2128).ssl_version to instead set the corresponding SSLContext.minimum_version
and SSLContext.maximum_version values. Regardless of ssl_version passed
SSLContext objects are now constructed using ssl.PROTOCOL_TLS_CLIENT (#2110).SSLContext.minimum_version to be TLSVersion.TLSv1_2 in line with Python 3.10 (#2373).ProxyError to wrap any connection error (timeout, TLS, DNS) that occurs when connecting to the proxy (#2482).urllib3.util.create_urllib3_context to not override the system cipher suites with
a default value. The new default will be cipher suites configured by the operating system (#2168).multipart/form-data header parameter formatting matches the WHATWG HTML Standard as of 2021-06-10. Control characters in filenames are no longer percent encoded (#2257).urllib3.HTTPConnection.getresponse to return an instance of urllib3.HTTPResponse instead of http.client.HTTPResponse (#2648).HTTPResponse.getheaders() method to return a list of key-value tuples to match CPython (#1543).ssl module isn't available from SSLError to ImportError (#2589).HTTPConnection.request() to always use lowercase chunk boundaries when sending requests with Transfer-Encoding: chunked (#2515).enforce_content_length default to True, preventing silent data loss when reading streamed responses (#2514).HTTPHeaderDict to use dict instead of collections.OrderedDict for better performance (#2080).urllib3.contrib.pyopenssl module to wrap OpenSSL.SSL.Error with ssl.SSLError in PyOpenSSLContext.load_cert_chain (#2628).socket.error to OSError (#2120).HTTPConnection and HTTPSConnection constructors to be keyword-only except host and port (#1985).urllib3.util.is_connection_dropped() to use HTTPConnection.is_connected (#1985).HTTPConnection.getresponse() to set the socket timeout from HTTPConnection.timeout value before reading
data from the socket. This previously was done manually by the HTTPConnectionPool calling HTTPConnection.sock.settimeout(...) (#1985)._proxy_host property to _tunnel_host in HTTPConnectionPool to more closely match how the property is used (value in HTTPConnection.set_tunnel()) (#1985).Retry.BACK0FF_MAX to be Retry.DEFAULT_BACKOFF_MAX.SSLContext.check_hostname when possible (#2452).server_hostname to behave like other parameters only used by HTTPSConnectionPool (#2537).blocksize to 16KB to match OpenSSL's default read amounts (#2348).urllib3.contrib.pyopenssl module which will be removed in urllib3 v2.1.0 (#2691).urllib3.contrib.securetransport module which will be removed in urllib3 v2.1.0 (#2692).ssl_version option in favor of ssl_minimum_version. ssl_version will be removed in urllib3 v2.1.0 (#2110).strict parameter as it's not longer needed in Python 3.x. It will be removed in urllib3 v2.1.0 (#2267)NewConnectionError.pool attribute which will be removed in urllib3 v2.1.0 (#2271).format_header_param_html5 and format_header_param in favor of format_multipart_header_param (#2257).RequestField.header_formatter parameter which will be removed in urllib3 v2.1.0 (#2257).HTTPSConnection.set_cert() method. Instead pass parameters to the HTTPSConnection constructor (#1985).HTTPConnection.request_chunked() method which will be removed in urllib3 v2.1.0. Instead pass chunked=True to HTTPConnection.request() (#1985).PoolManager with many distinct origins would cause connection pools to be closed while requests are in progress (#1252).HTTPConnection instance would erroneously reuse the socket read timeout value from reading the previous response instead of a newly configured connect timeout.
Instead now if HTTPConnection.timeout is updated before sending the next request the new timeout value will be used (#2645).socket.error.errno when raised from pyOpenSSL's OpenSSL.SSL.SysCallError (#2118).HTTPSConnection.socket_options to match HTTPConnection (#2213).headers would be modified by the remove_headers_on_redirect feature (#2272).urllib3.util.connection.create_connection() (#2277).HTTPConnection.connect() fails (#2571).Replaced deprecated dash-separated setuptools entries in setup.cfg .
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
setup.cfg. (#3461)ECONNRESET instead of EPROTOTYPE in its newer versions. (#3416)Full Changelog: 1.26.19...1.26.20
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financi
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support for 2023. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Proxy-Authorization header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_on_redirect.Full Changelog: https://github.com/urllib3/urllib3/compare/1.26.18...1.26.19
Note that due to an issue with our release automation, no multiple.intoto.jsonl file is available for this release.
Added the Proxy-Authorization header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_on_redirect.
Fixed handling of OpenSSL 3.2.0 new error message for misconfiguring an HTTP proxy as HTTPS. (#3405)
Made body stripped from HTTP requests changing the request method to GET after HTTP 303 "See Other" redirect responses. (GHSA-g4mx-q9vg-27p4)
Added the Cookie header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set vi
Cookie header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_on_redirect. (GHSA-v845-jxx5-vc9f)Fixed thread-safety issue where accessing a PoolManager with many distinct origins would cause connection pools to be closed while requests are in pro
PoolManager with many distinct origins would cause connection pools to be closed while requests are in progress (#2954)Fix socket timeout value when HTTPConnection is reused
Removed deprecated HTTPResponse.getheaders() calls in urllib3.contrib module.
HTTPResponse.getheaders() calls in urllib3.contrib module.Deprecated the HTTPResponse.getheaders() and HTTPResponse.getheader() methods.
HTTPResponse.getheaders() and HTTPResponse.getheader() methods.<4 in the Requires-Python packaging metadata field.Deprecated the urllib3[secure] extra and the urllib3.contrib.pyopenssl module. Both will be removed in v2.x. See this GitHub issue for justification a…
urllib3[secure] extra and the urllib3.contrib.pyopenssl module. Both will be removed in v2.x. See this GitHub issue for justification and info on how to migrate.If you or your organization rely on urllib3 consider supporting us via [GitHub Sponsors](https://github.com/sponsors/urllib3).
If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.
:warning: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
If you or your organization rely on urllib3 consider supporting us via [GitHub Sponsors](https://github.com/sponsors/urllib3).
If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.
:warning: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:closed_lock_with_key: This is the first release to be signed with Sigstore! You can verify the distributables using the .sig and .crt files included on this release.
ProxyError recommending configuring the proxy as HTTP instead of HTTPS could appear even when an HTTPS proxy wasn't configured.If you or your organization rely on urllib3 consider supporting us via [GitHub Sponsors](https://github.com/sponsors/urllib3).
If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.
:warning: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: This release will be the last release supporting Python 3.5. Please upgrade to a non-EOL Python version.
urllib3[brotli] extra to favor installing Brotli libraries that are still receiving updates like brotli and brotlicffi instead of brotlipy. This change does not impact behavior of urllib3, only which dependencies are installed.HTTPSConnection.connect() raises an exception.server_hostname being forwarded from PoolManager to HTTPConnectionPool
when requesting an HTTP URL. Should only be forwarded when requesting an HTTPS URL.Deprecated the Retry.MAX_BACKOFF class property in favor of Retry.DEFAULT_MAX_BACKOFF to better match the rest of the default parameter names. Retry.M…
If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.
:warning: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: This release will be the last release supporting Python 3.5. Please upgrade to a non-EOL Python version.
urllib3.exceptions.ProxyError when urllib3 detects that a proxy is configured to use HTTPS but the proxy itself appears to only use HTTP.Retry.MAX_BACKOFF class property in favor of Retry.DEFAULT_MAX_BACKOFF to better match the rest of the default parameter names. Retry.MAX_BACKOFF is removed in v2.0.ssl.match_hostname function from urllib3.packages.ssl_match_hostname to urllib3.util.ssl_match_hostname to ensure Python 3.10+ compatibility after being repackaged by downstream distributors.:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors
Fixed a bug with HTTPS hostname verification involving IP addresses and lack of SNI. (Issue #2400)
Fixed a bug where IPv6 braces weren't stripped during certificate hostname matching. (Issue #2240)
Deprecated the urllib3.contrib.ntlmpool module. urllib3 is not able to support it properly due to reasons listed in this issue. If you are a user of t…
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
urllib3.contrib.ntlmpool module. urllib3 is not able to support it properly due to reasons listed in this issue. If you are a user of this module please leave a comment.HTTPConnection.request_chunked() to not erroneously emit multiple Transfer-Encoding headers in the case that one is already specified.Retry.DEFAULT_ALLOWED_METHODS.If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors
Fixed deprecation warnings emitted in Python 3.10.
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
six library to 1.16.0.If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
SSLContext when connecting to HTTPS proxy during HTTPS requests. The default SSLContext now sets check_hostname=True.If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
Fixed bytes and string comparison issue with headers (Pull #2141)
Changed ProxySchemeUnknown error message to be more actionable if the user supplies a proxy URL without a scheme (Pull #2107)
If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
wrap_socket and CERT_REQUIRED wouldn't be imported properly on Python 2.7.8 and earlier (Pull #2052):warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
User-Agent headers would be sent if a User-Agent header key is passed as bytes (Pull #2047)Deprecated negotiating TLSv1 and TLSv1.1 by default. Users that still wish to use TLS earlier than 1.2 without a deprecation warning should opt-in exp…
:warning: IMPORTANT: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap
Added support for HTTPS proxies contacting HTTPS servers (Pull #1923, Pull #1806)
Deprecated negotiating TLSv1 and TLSv1.1 by default. Users that
still wish to use TLS earlier than 1.2 without a deprecation warning
should opt-in explicitly by setting ssl_version=ssl.PROTOCOL_TLSv1_1 (Pull #2002)
Starting in urllib3 v2.0: Connections that receive a DeprecationWarning will fail
Deprecated Retry options Retry.DEFAULT_METHOD_WHITELIST, Retry.DEFAULT_REDIRECT_HEADERS_BLACKLIST
and Retry(method_whitelist=...) in favor of Retry.DEFAULT_ALLOWED_METHODS,
Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT, and Retry(allowed_methods=...)
(Pull #2000) Starting in urllib3 v2.0: Deprecated options will be removed
Added default User-Agent header to every request (Pull #1750)
Added urllib3.util.SKIP_HEADER for skipping User-Agent, Accept-Encoding,
and Host headers from being automatically emitted with requests (Pull #2018)
Collapse transfer-encoding: chunked request data and framing into
the same socket.send() call (Pull #1906)
Send http/1.1 ALPN identifier with every TLS handshake by default (Pull #1894)
Properly terminate SecureTransport connections when CA verification fails (Pull #1977)
Don't emit an SNIMissingWarning when passing server_hostname=None
to SecureTransport (Pull #1903)
Disabled requesting TLSv1.2 session tickets as they weren't being used by urllib3 (Pull #1970)
Suppress BrokenPipeError when writing request body after the server
has closed the socket (Pull #1524)
Wrap ssl.SSLError that can be raised from reading a socket (e.g. "bad MAC")
into an urllib3.exceptions.SSLError (Pull #1939)
Fix retry backoff time parsed from Retry-After header when given in the HTTP date format. The HTTP date was parsed as the local timezone rather than a
Fix retry backoff time parsed from Retry-After header when given in the HTTP date format. The HTTP date was parsed as the local timezone rather than accounting for the timezone in the HTTP date (typically UTC) (#1932, #1935, #1938, #1949)
Fix issue where an error would be raised when the SSLKEYLOGFILE environment variable was set to the empty string. Now SSLContext.keylog_file is not set in this situation (#2016)
Added support for SSLKEYLOGFILE environment variable for logging TLS session keys with use with programs like Wireshark for decrypting captured web tr
Added support for SSLKEYLOGFILE environment variable for logging TLS session keys with use with programs like Wireshark for decrypting captured web traffic (Pull #1867)
Fixed loading of SecureTransport libraries on macOS Big Sur due to the new dynamic linker cache (Pull #1905)
Collapse chunked request bodies data and framing into one call to send() to reduce the number of TCP packets by 2-4x (Pull #1906)
Don't insert None into ConnectionPool if the pool was empty when requesting a connection (Pull #1866)
Avoid hasattr call in BrotliDecoder.decompress() (Pull #1858)
Added InvalidProxyConfigurationWarning which is raised when erroneously specifying an HTTPS proxy URL. urllib3 doesn't currently support connecting to
Added InvalidProxyConfigurationWarning which is raised when erroneously specifying an HTTPS proxy URL. urllib3 doesn't currently support connecting to HTTPS proxies but will soon be able to and we would like users to migrate properly without much breakage.
See this GitHub issue for more information on how to fix your proxy config. (Pull #1851)
Drain connection after PoolManager redirect (Pull #1817)
Ensure load_verify_locations raises SSLError for all backends (Pull #1812)
Rename VerifiedHTTPSConnection to HTTPSConnection (Pull #1805)
Allow the CA certificate data to be passed as a string (Pull #1804)
Raise ValueError if method contains control characters (Pull #1800)
Add __repr__ to Timeout (Pull #1795)
Drop support for EOL Python 3.4 (Pull #1774)
Drop support for EOL Python 3.4 (Pull #1774)
Optimize _encode_invalid_chars (Pull #1787)
Preserve chunked parameter on retries (Pull #1715, Pull #1734)
Preserve chunked parameter on retries (Pull #1715, Pull #1734)
Allow unset SERVER_SOFTWARE in App Engine (Pull #1704, Issue #1470)
Fix issue where URL fragment was sent within the request target. (Pull #1732)
Fix issue where an empty query section in a URL would fail to parse. (Pull #1732)
Remove TLS 1.3 support in SecureTransport due to Apple removing support (Pull #1703)
Fix issue where tilde (~) characters were incorrectly percent-encoded in the path. (Pull #1692)
Fix issue where tilde (~) characters were incorrectly percent-encoded in the path. (Pull #1692)
Add mitigation for BPO-37428 affecting Python <3.7.4 and OpenSSL 1.1.1+ which caused certificate verification to be enabled when using cert_reqs=CERT_
Add mitigation for BPO-37428 affecting Python <3.7.4 and OpenSSL 1.1.1+ which caused certificate verification to be enabled when using cert_reqs=CERT_NONE. (Issue #1682)
Propagate Retry-After header settings to subsequent retries. (Pull #1607)
Propagate Retry-After header settings to subsequent retries. (Pull #1607)
Fix edge case where Retry-After header was still respected even when explicitly opted out of. (Pull #1607)
Remove dependency on rfc3986 for URL parsing.
Fix issue where URLs containing invalid characters within Url.auth would raise an exception instead of percent-encoding those characters.
Add support for HTTPResponse.auto_close = False which makes HTTP responses work well with BufferedReaders and other io module features. (Pull #1652)
Percent-encode invalid characters in URL for HTTPConnectionPool.request() (Pull #1673)
Change HTTPSConnection to load system CA certificates when ca_certs, ca_cert_dir, and ssl_context are unspecified. (Pull #1608, Issue #1603)
Change HTTPSConnection to load system CA certificates when ca_certs, ca_cert_dir, and ssl_context are unspecified. (Pull #1608, Issue #1603)
Upgrade bundled rfc3986 to v1.3.2. (Pull #1609, Issue #1605)
Change is_ipaddress to not detect IPvFuture addresses. (Pull #1583)
Change is_ipaddress to not detect IPvFuture addresses. (Pull #1583)
Change parse_url to percent-encode invalid characters within the path, query, and target components. (Pull #1586)
Add support for Google's Brotli package. (Pull #1572, Pull #1579)
Brotli package. (Pull #1572, Pull #1579)Require and validate certificates by default when using HTTPS (Pull #1507)
Require and validate certificates by default when using HTTPS (Pull #1507)
Upgraded urllib3.utils.parse_url() to be RFC 3986 compliant. (Pull #1487)
Added support for key_password for HTTPSConnectionPool to use encrypted key_file without creating your own SSLContext object. (Pull #1489)
Add TLSv1.3 support to CPython, pyOpenSSL, and SecureTransport SSLContext implementations. (Pull #1496)
Switched the default multipart header encoder from RFC 2231 to HTML 5 working draft. (Issue #303, Pull #1492)
Fixed issue where OpenSSL would block if an encrypted client private key was given and no password was given. Instead an SSLError is raised. (Pull #1489)
Added support for Brotli content encoding. It is enabled automatically if brotlipy package is installed which can be requested with urllib3[brotli] extra. (Pull #1532)
Drop ciphers using DSS key exchange from default TLS cipher suites. Improve default ciphers when using SecureTransport. (Pull #1496)
Implemented a more efficient HTTPResponse.__iter__() method. (Issue #1483)
Apply fix for CVE-2019-9740. (Pull #1591)
Apply fix for CVE-2019-9740. (Pull #1591)
Your coding agent can read these notes before it upgrades. Set up the MCP server →