{"id":"CVE-2021-28363","aliases":["GHSA-5phf-pp7p-vc2r","PYSEC-2021-59"],"title":"Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection","summary":"Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","vendor":"urllib3","product":"urllib3","ecosystem":"pip","affected":["urllib3 >= 1.26.0, < 1.26.4"],"patched":["urllib3 1.26.4"],"published":"2021-03-19","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-5phf-pp7p-vc2r","references":[{"url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28363"},{"url":"https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2021-59.yaml"},{"url":"https://github.com/pypa/advisory-db/tree/main/vulns/urllib3/PYSEC-2021-59.yaml"},{"url":"https://github.com/urllib3/urllib3"},{"url":"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst#1264-2021-03-15"},{"url":"https://github.com/urllib3/urllib3/commits/main"},{"url":"https://github.com/urllib3/urllib3/releases/tag/1.26.4"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4S65ZQVZ2ODGB52IC7VJDBUK4M5INCXL"},{"url":"https://pypi.org/project/urllib3/1.26.4"},{"url":"https://security.gentoo.org/glsa/202107-36"},{"url":"https://security.gentoo.org/glsa/202305-02"},{"url":"https://security.netapp.com/advisory/ntap-20240621-0007"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"tags":["osv","pip"],"epss":0.02109,"epssPercentile":0.80975,"ingestedAt":"2026-07-08T18:25:46.043Z","slug":"CVE-2021-28363","body":"## Overview\n\n### Impact\n\nUsers who are using an HTTPS proxy to issue HTTPS requests and haven't configured their own SSLContext via `proxy_config`.\nOnly the default SSLContext is impacted.\n\n### Patches\n\n[urllib3 >=1.26.4 has the issue resolved](https://github.com/urllib3/urllib3/releases/tag/1.26.4). urllib3<1.26 is not impacted due to not supporting HTTPS requests via HTTPS proxies.\n\n### Workarounds\n\nUpgrading is recommended as this is a minor release and not likely to break current usage.\n\nConfiguring an `SSLContext` with `check_hostname=True` and passing via `proxy_config` instead of relying on the default `SSLContext`\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [sethmichaellarson@gmail.com](mailto:sethmichaellarson@gmail.com)\n\n## Affected packages\n\n- `urllib3 >= 1.26.0, < 1.26.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `urllib3 1.26.4`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}