urllib3-lts 🛡️
The Long-Term Support Security Release for urllib3.
This ecosystem backports critical security fixes to legacy Python environments (3.7 & 3.8) that official maintainers have dropped.
🏆 Patch Status (v2025.66471)
This release secures 941M+ downloads against the following vulnerabilities:
🏆 Patch Status (v2026.21441)
This release secures 929M+ downloads against the following vulnerabilities:
| Vulnerability | Severity | Impact | Py3.7 | Py3.8 |
|---|---|---|---|---|
| CVE-2026-21441 | 🔴 HIGH | Infinite Sleep DoS + Decompression Bomb | 🛡️ Fixed | 🛡️ Fixed |
| CVE-2025-66471 | 🔴 HIGH | Compression Bomb DoS + Bytes Key Crash | 🛡️ Fixed | 🛡️ Fixed |
| CVE-2025-66418 | 🔴 HIGH | Nested Decompression DoS | 🛡️ Fixed | 🛡️ Fixed |
| CVE-2025-50182 | 🟡 MOD | Node.js Redirect Bypass | N/A | 🛡️ Fixed |
| CVE-2025-50181 | 🟡 MOD | Redirect Retry Bypass | 🛡️ Fixed | 🛡️ Fixed |
| CVE-2024-37891 | 🟡 MOD | Proxy-Auth Header Leak | 🛡️ Fixed | N/A |
📦 Usage
Standard Installation:
pip install urllib3-lts
This meta-package automatically detects your Python version and installs the correct secured backport.
🌐 OmniPKG Security Scanning
This package is maintained as part of the OmniPKG ecosystem — a Python
environment manager with built-in CVE scanning. Scanning is performed via
pip audit by default, with Safety as
an optional upgrade.
pip install omnipkg
omnipkg reset -y
# -> Scans all installed packages for CVEs
# -> urllib3-lts will show 0 issues for all patched CVEs above
Maintained by 1minds3t.
🚧 Coming Soon: omnipkg-runtime
We are building a runtime enforcer that allows configurable WARN or BLOCK policies for unpatched vulnerabilities. Stay tuned.
⚠️ Important: Installation for Python 3.7-3.8
Before installing urllib3-lts, uninstall any existing urllib3:
pip uninstall urllib3 -y
pip install urllib3-lts
This ensures you get the security patches. If you install urllib3-lts without removing urllib3 first, other packages may reinstall the vulnerable version.
Alternative: Pin in requirements.txt
urllib3-lts-py37==2026.21441.1 ; python_version<'3.8'
urllib3-lts-py38==2026.21441 ; python_version>='3.8' and python_version<'3.9'
Release files for urllib3-lts 2026.21441.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| urllib3_lts-2026.21441.1.tar.gz | 4.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| urllib3_lts-2026.21441.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 8.4 kB
Release files / urllib3_lts-2026.21441.1.tar.gz
| Download URL | urllib3_lts-2026.21441.1.tar.gz |
|---|---|
| Size | 4.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1fc3d1d8811a334cbeb5eb95218ec789e9b574576840ec73f4c195e0a7793354
|
|
BLAKE2b-256 checksum How to use checksums |
c36e5a52ab167965c48a744e2f656eb65b828a0a4781b37802ce6e01451ea2bf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.
Transparency logRelease files / urllib3_lts-2026.21441.1-py3-none-any.whl
| Download URL | urllib3_lts-2026.21441.1-py3-none-any.whl |
|---|---|
| Size | 3.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3cdfc420f77ab7823c982a8887b2e3b68c3e141a1fc04001d2bf67597e6d91a5
|
|
BLAKE2b-256 checksum How to use checksums |
95b42b61102fafd7827fc2dea99272fab2fe254d094c82f1941e4e00db3ed536
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.
Transparency log