urllib3-lts-py38 🛡️
Security Backport for Python 3.8 Base: urllib3 v2.x | Patch Level: 2026.21441 | Auditor: 1minds3t
🚨 Security Matrix (Cumulative)
This release provides a hardened backport for Python 3.8, mitigating 5 Critical/High/Moderate Vulnerabilities identified between 2025 and 2026.
| CVE ID | Severity | Description | Status |
|---|---|---|---|
| CVE-2026-21441 | 🔴 HIGH | Infinite Sleep DoS: Limits Retry-After to 6 hours max. |
🛡️ FIXED |
| CVE-2025-66471 | 🔴 HIGH | Header/Collection Logic: Hardened internal data structures. | 🛡️ FIXED |
| CVE-2025-66418 | 🔴 HIGH | Decompression DoS: Hard limit of 5 nested Content-Encoding layers, prevents CPU exhaustion via nested compression attacks. | 🛡️ FIXED |
| CVE-2025-50182 | 🟡 MOD | Node.js Redirect Bypass: Enforces manual redirect control in emscripten backend. | 🛡️ FIXED |
| CVE-2025-50181 | 🟡 MOD | Redirect Security Bypass: Fixed PoolManager to correctly disable redirects when retries=False. |
🛡️ FIXED |
🛠️ Patch Architecture
Unlike standard upstream releases, this LTS version is specifically tuned for Python 3.8:
- Targeted Fixes: Only security-critical logic was backported; "modernization" noise (Python 3.14+ compatibility) was stripped to maintain a minimal diff.
- Resource Safety: Implemented mandatory
retry_after_maxand lazy decompression guards to prevent resource hanging.
📦 Installation
pip install urllib3-lts-py38==2026.21441
## 🌐 OmniPKG Security Scanning
This package is maintained as part of the **OmniPKG** ecosystem — a Python
environment manager with built-in CVE scanning powered by
[Safety](https://pypi.org/project/safety/) or pip audit as a fallback.
When you run `omnipkg reset`, it automatically audits all installed packages
against the Safety vulnerability database and flags any known CVEs:
```bash
pip install omnipkg
omnipkg reset -y
# -> Performs security scan across all installed packages
# -> Reports CVEs, audit status, and affected versions
# -> urllib3-lts-py38 will show 0 issues for the patched CVEs above
Maintained by 1minds3t.
## ⚠️ Critical Installation Warning
**You MUST uninstall the standard `urllib3` before installing this package to avoid namespace conflicts:**
```bash
pip uninstall urllib3 -y
pip install urllib3-lts-py38
All patches verified via omnipatcher manual human review on 2026-02-22.
Release files for urllib3-lts-py38 2026.21441.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| urllib3_lts_py38-2026.21441.1.tar.gz | 179.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| urllib3_lts_py38-2026.21441.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 304.9 kB
Release files / urllib3_lts_py38-2026.21441.1.tar.gz
| Download URL | urllib3_lts_py38-2026.21441.1.tar.gz |
|---|---|
| Size | 179.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3c692fc812a1f50b9df9dfd37528ad652eba6072b838869d8f7b7e07a8dc9adf
|
|
BLAKE2b-256 checksum How to use checksums |
165517fe73e3e669c9e8895630bad5cc8d90573eec7f3a5d5ecf5c1373836cb9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.
Transparency logRelease files / urllib3_lts_py38-2026.21441.1-py3-none-any.whl
| Download URL | urllib3_lts_py38-2026.21441.1-py3-none-any.whl |
|---|---|
| Size | 125.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8703a968fc3aed5f66c55b22683cf97400161bceaa836acff96e924b1e8086ef
|
|
BLAKE2b-256 checksum How to use checksums |
dd59d492471a841c8c0f21cecf6179ec83e09dec55e0173a3e946236151248a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.
Transparency log