# urllib3-lts-py37 🛡️
**Security Backport for Python 3.7**
Base: `urllib3 v2.0.7` | Patch Level: `2026.21441`
## 🚨 Security Fixes Included
This release backports fixes for **5 Critical/High/Moderate Vulnerabilities** found in the official `v2.0.7` release.
| CVE ID | Severity | Description | Status |
|:---|:---|:---|:---|
| **CVE-2026-21441** | 🔴 HIGH | **Decompression/Retry DoS:** Guarded redirect streaming & capped Retry-After. | 🛡️ **FIXED** |
| **CVE-2025-66471** | 🔴 HIGH | **Compression Bomb DoS:** Added `max_length` limits to decompression. | 🛡️ **FIXED** |
| **CVE-2025-66418** | 🔴 HIGH | **Unbounded Links:** Limited decompression chain depth. | 🛡️ **FIXED** |
| **CVE-2025-50181** | 🟡 MOD | **Redirect Bypass:** Fixed retry logic when redirects disabled. | 🛡️ **FIXED** |
| **CVE-2024-37891** | 🟡 MOD | **Header Leak:** Strips Proxy-Authorization on redirect. | 🛡️ **FIXED** |
## 📦 Installation
```bash
pip install urllib3-lts-py37==2026.21441
🌐 The OmniPKG Ecosystem
Maintained by 1minds3t.
Manage your environment:
pip install omnipkg
omnipkg reset -y
⚠️ Installation Warning
Uninstall urllib3 before installing this package:
pip uninstall urllib3 -y
pip install urllib3-lts-py37
This ensures the security patches are applied and not overwritten.
Release files for urllib3-lts-py37 2026.21441.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| urllib3_lts_py37-2026.21441.1.tar.gz | 153.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| urllib3_lts_py37-2026.21441.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 278.1 kB
Release files / urllib3_lts_py37-2026.21441.1.tar.gz
| Download URL | urllib3_lts_py37-2026.21441.1.tar.gz |
|---|---|
| Size | 153.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
debe82001e7a21564666f6dea7b69550de2e0d92b264edbd07b0b48d8315004d
|
|
BLAKE2b-256 checksum How to use checksums |
c997ec7d43168fb881e15cac2cc9949ccfca17006f27ddac97333cca6eb4060a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 22, 2026.
Transparency logRelease files / urllib3_lts_py37-2026.21441.1-py3-none-any.whl
| Download URL | urllib3_lts_py37-2026.21441.1-py3-none-any.whl |
|---|---|
| Size | 125.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e6783627741565464f003f74b6415c8f0a70c37a04ffd64112c5d413ab0ad14b
|
|
BLAKE2b-256 checksum How to use checksums |
d384aca390c76d8e54af6afe95a0cf5b9e992f31b93c2b36e61beab31e075bd7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 22, 2026.
Transparency log