Skip to content
Critical Security Flaw in Python urllib3 Exploited

Critical Security Flaw in Python urllib3 Exploited

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •CISA confirmed exploitation of vulnerabilities in python-urllib3.
  • •High severity issues include TLS configuration flaws and memory buffering risks.
  • •Immediate updates to python-urllib3 version 2.8.0 are recommended.

CISA has confirmed the exploitation of a critical vulnerability in the Python urllib3 library, affecting multiple Fedora versions. The vulnerability allows the TLS configuration for HTTPS proxies to be ignored or overridden, posing significant risks to data security. Additionally, two other issues could lead to unbounded memory buffering and infinite loops during streaming. The affected versions include python-urllib3 2.8.0, which has been updated to address these vulnerabilities. Users are urged to upgrade their systems immediately to mitigate risks. The vulnerabilities are rated high severity by upstream sources, with CVE identifiers GHSA-8988-9cw3-xx77, GHSA-vxq7-64xx-v4gw, and GHSA-gh4c-6fx4-qh6g. The updates are available via the dnf package manager. This incident highlights the urgency for system administrators to apply the patches to prevent potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
Update to python-urllib3 2.8.0 released
Version 2.8.0 addresses three critical security vulnerabilities, including TLS configuration issues.
Linuxsecurity
2026-09-29
CISA confirms exploitation
CISA has confirmed that the vulnerabilities in python-urllib3 are being actively exploited in the wild.
Linuxsecurity

More articles in this cluster (5)

Following this threat?

Track Fedora in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed