Skip to main content
# urllib3-lts-py37 🛡️

**Security Backport for Python 3.7**
Base: `urllib3 v2.0.7` | Patch Level: `2026.21441`

## 🚨 Security Fixes Included
This release backports fixes for **5 Critical/High/Moderate Vulnerabilities** found in the official `v2.0.7` release.

| CVE ID | Severity | Description | Status |
|:---|:---|:---|:---|
| **CVE-2026-21441** | 🔴 HIGH | **Decompression/Retry DoS:** Guarded redirect streaming & capped Retry-After. | 🛡️ **FIXED** |
| **CVE-2025-66471** | 🔴 HIGH | **Compression Bomb DoS:** Added `max_length` limits to decompression. | 🛡️ **FIXED** |
| **CVE-2025-66418** | 🔴 HIGH | **Unbounded Links:** Limited decompression chain depth. | 🛡️ **FIXED** |
| **CVE-2025-50181** | 🟡 MOD | **Redirect Bypass:** Fixed retry logic when redirects disabled. | 🛡️ **FIXED** |
| **CVE-2024-37891** | 🟡 MOD | **Header Leak:** Strips Proxy-Authorization on redirect. | 🛡️ **FIXED** |

## 📦 Installation
```bash
pip install urllib3-lts-py37==2026.21441

🌐 The OmniPKG Ecosystem

Maintained by 1minds3t.

Manage your environment:

pip install omnipkg
omnipkg reset -y

⚠️ Installation Warning

Uninstall urllib3 before installing this package:

pip uninstall urllib3 -y
pip install urllib3-lts-py37

This ensures the security patches are applied and not overwritten.

Release files for urllib3-lts-py37 2026.21441.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for urllib3-lts-py37 2026.21441.1
File Size Uploaded
urllib3_lts_py37-2026.21441.1.tar.gz 153.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for urllib3-lts-py37 2026.21441.1
File Interpreter ABI Platform
urllib3_lts_py37-2026.21441.1-py3-none-any.whl Python 3 none any Details

Total release size: 278.1 kB

Release files / urllib3_lts_py37-2026.21441.1.tar.gz

Download URL urllib3_lts_py37-2026.21441.1.tar.gz
Size 153.1 kB
Tags Source
SHA-256 checksum
How to use checksums
debe82001e7a21564666f6dea7b69550de2e0d92b264edbd07b0b48d8315004d
BLAKE2b-256 checksum
How to use checksums
c997ec7d43168fb881e15cac2cc9949ccfca17006f27ddac97333cca6eb4060a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 22, 2026.

Transparency log

Release files / urllib3_lts_py37-2026.21441.1-py3-none-any.whl

Download URL urllib3_lts_py37-2026.21441.1-py3-none-any.whl
Size 125.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e6783627741565464f003f74b6415c8f0a70c37a04ffd64112c5d413ab0ad14b
BLAKE2b-256 checksum
How to use checksums
d384aca390c76d8e54af6afe95a0cf5b9e992f31b93c2b36e61beab31e075bd7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 22, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2026.21441.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page