Files
buildroot/package/python-urllib3/python-urllib3.hash
Peter Korsgaard 8b606d9074 package/python-urllib3: security bump to version 2.7.0
Fixes the following security issues:

CVE-2026-44431: Sensitive headers forwarded across origins in proxied
low-level redirects

https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc

CVE-2026-44432: Decompression-bomb safeguards bypassed in parts of the
streaming API

https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j

For more details, see the release notes:
https://urllib3.readthedocs.io/en/stable/changelog.html#id1

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-05-26 19:40:36 +02:00

6 lines
331 B
Plaintext

# md5, sha256 from https://pypi.org/pypi/urllib3/json
md5 e79707b798a66c8165c9c441440f4e80 urllib3-2.7.0.tar.gz
sha256 231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c urllib3-2.7.0.tar.gz
# Locally computed sha256 checksums
sha256 130e3a64d5fdd5d096a752694634a7d9df284469de86e5732100268041e3d686 LICENSE.txt