Skip to main content

urllib3-lts-py38 🛡️

Security Backport for Python 3.8 Base: urllib3 v2.x | Patch Level: 2026.21441 | Auditor: 1minds3t

🚨 Security Matrix (Cumulative)

This release provides a hardened backport for Python 3.8, mitigating 5 Critical/High/Moderate Vulnerabilities identified between 2025 and 2026.

CVE ID Severity Description Status
CVE-2026-21441 🔴 HIGH Infinite Sleep DoS: Limits Retry-After to 6 hours max. 🛡️ FIXED
CVE-2025-66471 🔴 HIGH Header/Collection Logic: Hardened internal data structures. 🛡️ FIXED
CVE-2025-66418 🔴 HIGH Decompression DoS: Hard limit of 5 nested Content-Encoding layers, prevents CPU exhaustion via nested compression attacks. 🛡️ FIXED
CVE-2025-50182 🟡 MOD Node.js Redirect Bypass: Enforces manual redirect control in emscripten backend. 🛡️ FIXED
CVE-2025-50181 🟡 MOD Redirect Security Bypass: Fixed PoolManager to correctly disable redirects when retries=False. 🛡️ FIXED

🛠️ Patch Architecture

Unlike standard upstream releases, this LTS version is specifically tuned for Python 3.8:

  • Targeted Fixes: Only security-critical logic was backported; "modernization" noise (Python 3.14+ compatibility) was stripped to maintain a minimal diff.
  • Resource Safety: Implemented mandatory retry_after_max and lazy decompression guards to prevent resource hanging.

📦 Installation

pip install urllib3-lts-py38==2026.21441
## 🌐 OmniPKG Security Scanning

This package is maintained as part of the **OmniPKG** ecosystem — a Python
environment manager with built-in CVE scanning powered by
[Safety](https://pypi.org/project/safety/) or pip audit as a fallback.

When you run `omnipkg reset`, it automatically audits all installed packages
against the Safety vulnerability database and flags any known CVEs:

```bash
pip install omnipkg
omnipkg reset -y
# -> Performs security scan across all installed packages
# -> Reports CVEs, audit status, and affected versions
# -> urllib3-lts-py38 will show 0 issues for the patched CVEs above

Maintained by 1minds3t.



## ⚠️ Critical Installation Warning

**You MUST uninstall the standard `urllib3` before installing this package to avoid namespace conflicts:**

```bash
pip uninstall urllib3 -y
pip install urllib3-lts-py38


All patches verified via omnipatcher manual human review on 2026-02-22.

Release files for urllib3-lts-py38 2026.21441.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for urllib3-lts-py38 2026.21441.1
File Size Uploaded
urllib3_lts_py38-2026.21441.1.tar.gz 179.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for urllib3-lts-py38 2026.21441.1
File Interpreter ABI Platform
urllib3_lts_py38-2026.21441.1-py3-none-any.whl Python 3 none any Details

Total release size: 304.9 kB

Release files / urllib3_lts_py38-2026.21441.1.tar.gz

Download URL urllib3_lts_py38-2026.21441.1.tar.gz
Size 179.2 kB
Tags Source
SHA-256 checksum
How to use checksums
3c692fc812a1f50b9df9dfd37528ad652eba6072b838869d8f7b7e07a8dc9adf
BLAKE2b-256 checksum
How to use checksums
165517fe73e3e669c9e8895630bad5cc8d90573eec7f3a5d5ecf5c1373836cb9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.

Transparency log

Release files / urllib3_lts_py38-2026.21441.1-py3-none-any.whl

Download URL urllib3_lts_py38-2026.21441.1-py3-none-any.whl
Size 125.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8703a968fc3aed5f66c55b22683cf97400161bceaa836acff96e924b1e8086ef
BLAKE2b-256 checksum
How to use checksums
dd59d492471a841c8c0f21cecf6179ec83e09dec55e0173a3e946236151248a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2026.21441.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page