{"id":"GHSA-5phf-pp7p-vc2r","summary":"Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection","details":"### Impact\n\nUsers who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via `proxy_config`.\nOnly the default SSLContext is impacted.\n\n### Patches\n\n[urllib3 \u003e=1.26.4 has the issue resolved](https://github.com/urllib3/urllib3/releases/tag/1.26.4). urllib3\u003c1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.\n\n### Workarounds\n\nUpgrading is recommended as this is a minor release and not likely to break current usage.\n\nConfiguring an `SSLContext` with `check_hostname=True` and passing via `proxy_config` instead of relying on the default `SSLContext`\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [sethmichaellarson@gmail.com](mailto:sethmichaellarson@gmail.com)","aliases":["CVE-2021-28363","PYSEC-2021-59"],"modified":"2026-07-08T06:28:26.820684687Z","published":"2021-03-19T19:42:11Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-03-19T19:41:48Z","nvd_published_at":"2021-03-15T18:15:00Z","cwe_ids":["CWE-295"]},"references":[{"type":"WEB","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28363"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-59.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-db/tree/main/vulns/urllib3/PYSEC-2021-59.yaml"},{"type":"PACKAGE","url":"https://github.com/urllib3/urllib3"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst#1264-2021-03-15"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/commits/main"},{"type":"WEB","url":"https://github.com/urllib3/urllib3/releases/tag/1.26.4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL"},{"type":"WEB","url":"https://pypi.org/project/urllib3/1.26.4"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202107-36"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-02"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240621-0007"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"affected":[{"package":{"name":"urllib3","ecosystem":"PyPI","purl":"pkg:pypi/urllib3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.26.0"},{"fixed":"1.26.4"}]}],"versions":["1.26.0","1.26.1","1.26.2","1.26.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-5phf-pp7p-vc2r/GHSA-5phf-pp7p-vc2r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}