CVE-2026-97687 urllib3 HTTPS 代理 TLS 校验绕过漏洞
影响攻击者可冒充 HTTPS 代理,窃取或篡改转发流量
urllib3 是 Python 的 HTTP 客户端库。在 1.26.0 至 2.8.0 版本中,针对目标服务器的 TLS 配置会被错误地应用到 HTTPS 代理连接上,导致代理 TLS 校验策略被覆盖。攻击者可在中间人位置冒充 HTTPS 代理,从而观察或修改经代理转发的流量。
影响范围
urllib3 1.26.0 至 2.8.0(不含 2.8.0)版本受影响,2.8.0 已修复。
漏洞详情
漏洞源于目标服务器与 HTTPS 代理的 TLS 设置未正确隔离,proxy_ssl_context、ssl_context、cert_reqs、verify_mode 等配置会相互污染。当设置 cert_reqs=CERT_NONE 时,会就地覆盖 proxy_ssl_context.verify_mode,且该修改会持续生效,使后续复用同一 context 的连接在访问 HTTPS 代理时不再校验证书。攻击者据此可冒充代理,读取或篡改转发流量,甚至获取目标 TLS 客户端证书。
利用条件与风险
利用前提是应用使用 HTTPS 代理并配置了本应独立的目标服务器 TLS 参数,且攻击者能实施中间人拦截。实战中可能导致代理层证书校验被静默关闭,造成敏感流量泄露或篡改。
修复建议
升级至 urllib3 2.8.0 或更高版本。临时缓解措施为:避免对代理连接使用 CERT_NONE,确保代理与目标服务器的 TLS 配置相互独立,暂无其他公开缓解信息。
urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker’s certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.