Skip to main content

urllib3-lts 🛡️

The Long-Term Support Security Release for urllib3.

This ecosystem backports critical security fixes to legacy Python environments (3.7 & 3.8) that official maintainers have dropped.

🏆 Patch Status (v2025.66471)

This release secures 941M+ downloads against the following vulnerabilities:

🏆 Patch Status (v2026.21441)

This release secures 929M+ downloads against the following vulnerabilities:

Vulnerability Severity Impact Py3.7 Py3.8
CVE-2026-21441 🔴 HIGH Infinite Sleep DoS + Decompression Bomb 🛡️ Fixed 🛡️ Fixed
CVE-2025-66471 🔴 HIGH Compression Bomb DoS + Bytes Key Crash 🛡️ Fixed 🛡️ Fixed
CVE-2025-66418 🔴 HIGH Nested Decompression DoS 🛡️ Fixed 🛡️ Fixed
CVE-2025-50182 🟡 MOD Node.js Redirect Bypass N/A 🛡️ Fixed
CVE-2025-50181 🟡 MOD Redirect Retry Bypass 🛡️ Fixed 🛡️ Fixed
CVE-2024-37891 🟡 MOD Proxy-Auth Header Leak 🛡️ Fixed N/A

📦 Usage

Standard Installation:

pip install urllib3-lts

This meta-package automatically detects your Python version and installs the correct secured backport.

🌐 OmniPKG Security Scanning

This package is maintained as part of the OmniPKG ecosystem — a Python environment manager with built-in CVE scanning. Scanning is performed via pip audit by default, with Safety as an optional upgrade.

pip install omnipkg
omnipkg reset -y
# -> Scans all installed packages for CVEs
# -> urllib3-lts will show 0 issues for all patched CVEs above

Maintained by 1minds3t.

🚧 Coming Soon: omnipkg-runtime

We are building a runtime enforcer that allows configurable WARN or BLOCK policies for unpatched vulnerabilities. Stay tuned.

⚠️ Important: Installation for Python 3.7-3.8

Before installing urllib3-lts, uninstall any existing urllib3:

pip uninstall urllib3 -y
pip install urllib3-lts

This ensures you get the security patches. If you install urllib3-lts without removing urllib3 first, other packages may reinstall the vulnerable version.

Alternative: Pin in requirements.txt

urllib3-lts-py37==2026.21441.1 ; python_version<'3.8'
urllib3-lts-py38==2026.21441 ; python_version>='3.8' and python_version<'3.9'

Release files for urllib3-lts 2026.21441.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for urllib3-lts 2026.21441.1
File Size Uploaded
urllib3_lts-2026.21441.1.tar.gz 4.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for urllib3-lts 2026.21441.1
File Interpreter ABI Platform
urllib3_lts-2026.21441.1-py3-none-any.whl Python 3 none any Details

Total release size: 8.4 kB

Release files / urllib3_lts-2026.21441.1.tar.gz

Download URL urllib3_lts-2026.21441.1.tar.gz
Size 4.7 kB
Tags Source
SHA-256 checksum
How to use checksums
1fc3d1d8811a334cbeb5eb95218ec789e9b574576840ec73f4c195e0a7793354
BLAKE2b-256 checksum
How to use checksums
c36e5a52ab167965c48a744e2f656eb65b828a0a4781b37802ce6e01451ea2bf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.

Transparency log

Release files / urllib3_lts-2026.21441.1-py3-none-any.whl

Download URL urllib3_lts-2026.21441.1-py3-none-any.whl
Size 3.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3cdfc420f77ab7823c982a8887b2e3b68c3e141a1fc04001d2bf67597e6d91a5
BLAKE2b-256 checksum
How to use checksums
95b42b61102fafd7827fc2dea99272fab2fe254d094c82f1941e4e00db3ed536
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 23, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2026.21441.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page