Medium severity6.5NVD Advisory· Published Mar 15, 2021· Updated Jun 17, 2026
CVE-2021-28363
CVE-2021-28363
Description
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
urllib3PyPI | >= 1.26.0, < 1.26.4 | 1.26.4 |
Affected products
5- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
- cpe:2.3:a:python:urllib3:*:*:*:*:*:*:*:*Range: >=1.26.0,<1.26.4
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- Python/urllib3description
Patches
Vulnerability mechanics
References
19- github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0nvdPatchThird Party AdvisoryWEB
- github.com/urllib3/urllib3/commits/mainnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5phf-pp7p-vc2rghsaADVISORY
- github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2rnvdMitigationThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-28363ghsaADVISORY
- pypi.org/project/urllib3/1.26.4/nvdThird Party Advisory
- security.gentoo.org/glsa/202107-36nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-59.yamlghsaWEB
- github.com/pypa/advisory-db/tree/main/vulns/urllib3/PYSEC-2021-59.yamlghsaWEB
- github.com/urllib3/urllib3/blob/main/CHANGES.rstghsaWEB
- github.com/urllib3/urllib3/releases/tag/1.26.4ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXLghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXLghsaWEB
- pypi.org/project/urllib3/1.26.4ghsaWEB
- security.gentoo.org/glsa/202305-02nvdWEB
- security.netapp.com/advisory/ntap-20240621-0007ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL/nvd
- security.netapp.com/advisory/ntap-20240621-0007/nvd
News mentions
0No linked articles in our index yet.